Hacker News new | ask | show | jobs
by kiwijimm 1887 days ago
Password expiry policies are useless. No one recommends using them. As has been pointed out already, the standards orgs and government cyber security departments advise not to have expiries. However most enterprises (I did a straw poll of all my friends and people they knew) still do it. I wrote about it here: https://jgandrews.com/posts/password-expiry-policies-dont-wo... back in January. Nothing makes sense about password expiry.