Hacker News new | ask | show | jobs
by tnbp 870 days ago
You should not require users to change their passwords periodically, as this will piss them off and make them use many weak passwords rather than one strong password. Only require a password change when there is reason to believe their old password has been compromised.