Hacker News new | ask | show | jobs
by tyingq 3321 days ago
Agreed. As it stands today, PCI, Sarbanes Oxley, HIPPA, and other drivers are used as hammers to force password change policies.

Even if they don't mention it directly, some audit firm tosses it in as a best practice to support something more generically stated in the standards.