4 ms·
> Passwords should be regularly rotated Disagree. I'd even call required rotation a smell. Requiring rotation leads to people coming up with passwords more fr
by mhluongo 4y ago
> Passwords should be regularly rotated
Disagree. I'd even call required rotation a smell.
Requiring rotation leads to people coming up with passwords more frequently, meaning they'll likely choose weaker passwords. On top of that, regular rotation isn't necessary for passwords generated independently by a password manager.
The issue here is that there's no way to deal with revocation / password changes if a service is compromised.
- nprateem 4y agoIt doesn't matter what you think. If someone's using a service that requires it and the tool doesn't allow it it's no good.
- mhluongo 4y agoI responded to that in the original comment. Whether or not a service requires rotation (bad practice), this tool won't work (can't handle compromised passwords).