Hacker News new | ask | show | jobs
by k4ch0w 1513 days ago
I do want to say there are legitimate reasons to have your users have a forced reset. For example, you’re upgrading your encryption, you migrated to a new IAM system, you’re handling of UTF8 could have been wrong or your meeting a new compliance standard that requires stricter passwords. I don’t know what happened with GitLab, but a telltale sign it’s bad is if they do it for you and not on your next login.