Hacker News new | past | comments | ask | show | jobs | submit login

Password rotation discourages password automation (password managers). Certificate rotation encourages (requires, really) certificate automation.



Wouldn't it be the opposite? If I had to rotate passwords frequently I'd want to use a password manager that could handle it for me.


There's no standard way for websites to rotate passwords through password managers.


Some password managers have automation to change passwords, but it's... janky. I think they've manually implemented stuff for some sites (and it works for some sites and managers, not all sites).


There is a way to indicate the URI to visit for change-password but not about how to interact with the document at that URI.

See `change-password` under https://en.wikipedia.org/wiki/Well-known_URI.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: