3 ms·
It used to be a good idea with things like AD, where pass-the-hash attacks worked and hashes would be static until changed, and in environments where hashes wer
by quacksilver 2y ago
It used to be a good idea with things like AD, where pass-the-hash attacks worked and hashes would be static until changed, and in environments where hashes were relatively exposed for cracking and used weak hashes.
Hopefully that is not the case now though, and I am surprised the advice has persisted... (though outdated gov standards probably played a part until recently)