3 ms·
While it is certainly correct to never enforce changing a password, I would argue that it is totally okay to expire it in certain scenarios. When my company set
by asimops 5y ago
While it is certainly correct to never enforce changing a password, I would argue that it is totally okay to expire it in certain scenarios.
When my company set up the Active Directory f.e. we put a LSA password filter[0] in place that checks against HIBP. The password policy was set to expire every 90 days, atleast 15 characters and dont enforce a history. The non existent history was clearly communicated and users are encouraged to just enter their existing password three times when it expires. That way there is only one place where the passwords are checked for leaks and they are already there in plain, so it is manageable and doesn't add that much attack surface.
[0]: Something like https://github.com/fblz/PassFilter https://github.com/fblz/PassFilter or https://github.com/rlabolle/hibppwdflt https://github.com/rlabolle/hibppwdflt