|
|
|
|
|
by asveikau
369 days ago
|
|
Sometimes when I log into a random website and I see a forced password reset, I wonder if it has been compromised, rather than setting a time-based expiry. If a site owner knows that certain accounts are part of a database breach or something, a reasonable step would be to force the users to change the password at next login. |
|