6 ms·
Your assumption is that there's zero time between a leak and the abuse. If my password reaches the abuser after it expires, then I have been saved by the rotati
by pontilanda 4y ago
Your assumption is that there's zero time between a leak and the abuse. If my password reaches the abuser after it expires, then I have been saved by the rotation.
Also rotation + "no reuse" policy essentially guarantees that eventually the password will be unique and not reused across services.
Side note: I despise rotation as much as the next guy, but I can see the value in it. If users used password managers, generated passwords and not reused passwords, then we wouldn't need such rules. But alas 1234567890 is a common password.
- Someone1234 4y ago> Your assumption is that there's zero time between a leak and the abuse. If my password reaches the abuser after it expires, then I have been saved by the rotation. Nope, that wasn't my assumption. What I said above applies there equally. > Also rotation + "no reuse" policy essentially guarantees that eventually the password will be unique and not reused across services. No it doesn't, in fact it increases password reuse and results in pattern-style passwords.