This practice is not recommended anymore, yet still found in many enterprises.

  • @[email protected]
    link
    fedilink
    23
    edit-2
    30 days ago

    oh i didn’t know that, are companies finally realizing that creating and trying to remember new passwords causes more trouble then keeping one really good password?

    • slazer2au
      link
      fedilink
      English
      630 days ago

      Only on accounts that have MFA is password rotation no longer recommended.

      If the account is non MFA protected password changes are still recommend.

      • @[email protected]
        link
        fedilink
        5
        edit-2
        30 days ago

        really? what’s the standard for that? like how often should you be rotating your password?

        I assumed many people forget their new passwords (because I often do) and become compromised than are protected by continually rotating passwords.

        • slazer2au
          link
          fedilink
          English
          230 days ago

          It’s one of the updated NIST recommendations, I don’t recall which one but it specifically calls out no password cycling for MFA protected accounts.