This practice is not recommended anymore, yet still found in many enterprises.

  • @Varyk
    link
    5
    edit-2
    28 days ago

    really? what’s the standard for that? like how often should you be rotating your password?

    I assumed many people forget their new passwords (because I often do) and become compromised than are protected by continually rotating passwords.

    • slazer2au
      link
      fedilink
      English
      228 days ago

      It’s one of the updated NIST recommendations, I don’t recall which one but it specifically calls out no password cycling for MFA protected accounts.