Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I actually blame the auditors.

In the case of password construction and complexity, we’ve learned that rotation and complexity leads to worse password practices.

https://pages.nist.gov/800-63-3/sp800-63b.html

However many large companies do not adhere to the latest NIST guidance (which is many years old by now).

This is why password complexity and rotation is still so nuts.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: