Hacker News new | ask | show | jobs
by milkthefat 3321 days ago
This is great, unfortunately considering this is only draft I imagine it will be a considerable amount of time to trickle down through the "compliance standards" we are required to enforce. I do look forward to the day I no longer have to change my password every 30 days though.
1 comments

Agreed. As it stands today, PCI, Sarbanes Oxley, HIPPA, and other drivers are used as hammers to force password change policies.

Even if they don't mention it directly, some audit firm tosses it in as a best practice to support something more generically stated in the standards.