Hacker News new | ask | show | jobs
by henry81 5670 days ago
Because expiring passwords is a horrible idea.

At the place I work at, most everyone just changes their password monthly like: "password1", "password2", etc.. Anything more difficult than that then they are likely to forget their password.

Another awful idea is locking people out if the password is wrong after 3 attempts. Then you have mischievous characters entering in 3 bogus passwords just to lock you out of your account and inconvenience you.

The whole concept of expiring passwords should be gotten rid of everywhere.