873
submitted 1 year ago by Stamets@startrek.website to c/memes@lemmy.ml
you are viewing a single comment's thread
view the rest of the comments
[-] andyburke@kbin.social 68 points 1 year ago

FWIW: these types of password rules are discouraged by NIST -

  1. Eliminate Periodic Resets

Many companies ask their users to reset their passwords every few months, thinking that any unauthorized person who obtained a user’s password will soon be locked out. However, frequent password changes can actually make security worse.

It’s difficult enough to remember one good password a year. And since users often have numerous passwords to remember already, they often resort to changing their passwords in predictable patterns, such as adding a single character to the end of their last password or replacing a letter with a symbol that looks like it (such as $ instead of S).

So if an attacker already knows a user’s previous password, it won’t be difficult to crack the new one. The NIST guidelines state that periodic password-change requirements should be removed for this reason.

[-] sparky678348@lemm.ee 4 points 1 year ago

Yes never made much sense to me either.

load more comments (7 replies)
this post was submitted on 23 Sep 2023
873 points (97.8% liked)

Memes

45987 readers
1529 users here now

Rules:

  1. Be civil and nice.
  2. Try not to excessively repost, as a rule of thumb, wait at least 2 months to do it if you have to.

founded 5 years ago
MODERATORS