Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Our penetration testers suggested we add password rotation, and I had to quote them the latest NIST guidelines which state "Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."

If they don't know better, it's not surprising other companies don't either.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: