3 ms·
> One, has forced password changes at 6 month intervals (not as good as 90 days, but better than many!) Forcing password changes reduces overall security, espe
by clcaev 4y ago
> One, has forced password changes at 6 month intervals (not as good as 90 days, but better than many!)
Forcing password changes reduces overall security, especially for infrequently accessed services. It only normalizes the reset workflow, and enables easier social engineering.
The NIST standard (800-53?) was updated to reflect this reality, and it no longer requires periodic password rotation.
- rdtwo 4y agoYeah not forcing password changes allows having a unique bank only password and reduces temptation to reuse