Hacker News new | ask | show | jobs
by dsacco 3322 days ago
We're talking about best practices; I didn't make any claim about how many people use password managers.

The point remains - if you want to follow password best practices and optimize for user safety, don't enforce arbitrary password changes. You're right about ordinary users - we should provide them with fewer opportunities to shoot themselves in the foot. The lower the frequency they have to focus on generating passwords, the better.