Hacker News new | ask | show | jobs
by amne 919 days ago
We have a linux user self-serve page where we can reset our passwords when they expire. The catch is we never use said password because all logins are done with keys but you can't login if your password is expired. So imagine someone "data-driven" getting rid of that page because it is rarely used.

Why do the passwords expire if they're not used? "best practice"