3 ms·
> The IT folks say that passwords have to change every 90 days This is explicitly not the NIST recommendation (the group in gov that sets some security standar
by wslack 6y ago
> The IT folks say that passwords have to change every 90 days
This is explicitly not the NIST recommendation (the group in gov that sets some security standards), but the word is not getting out quickly.
- random5634 6y agoFor a long time this must have been on the recommendation list - because password forms with insane complexity (12 charachters, upper, lower etc), but then non copy pastable forms and 60 day change requirements remained very common. The current IRS requirements are 90 day password changes. Ergo - many people write their passwords down in a text document next to the software launch icon. What I don't get - if your computer is hacked, and you force people to write down their passwords on the computer being hacked, they will even more easily be able to access the systems you have access to. Google seems to get this right. I have had same password for 20 years, if I login with a new device I use my MFA (no SMS). If I do a security sensitive op I need to login and do an MFA again (password reset etc). I imagine they actually monitor and rate limit bad login attempts etc. A 10 character password is really fine then in my view as an example.