This practice is not recommended anymore, yet still found in many enterprises.

  • @[email protected]
    link
    fedilink
    23
    edit-2
    30 days ago

    oh i didn’t know that, are companies finally realizing that creating and trying to remember new passwords causes more trouble then keeping one really good password?

    • slazer2au
      link
      English
      630 days ago

      Only on accounts that have MFA is password rotation no longer recommended.

      If the account is non MFA protected password changes are still recommend.

      • @[email protected]
        link
        fedilink
        5
        edit-2
        30 days ago

        really? what’s the standard for that? like how often should you be rotating your password?

        I assumed many people forget their new passwords (because I often do) and become compromised than are protected by continually rotating passwords.

        • @skittlebrau
          link
          630 days ago

          I have over 500 passwords in my password manager. I don’t know what I’d do without it.

        • slazer2au
          link
          English
          230 days ago

          It’s one of the updated NIST recommendations, I don’t recall which one but it specifically calls out no password cycling for MFA protected accounts.