Viking_Hippie@lemmy.dbzer0.com to Mildly Infuriating@lemmy.worldEnglish · edit-21 month agoThe inner fire of my hatred COULD melt steam beamsimagemessage-square51linkfedilinkarrow-up1520arrow-down115file-text
arrow-up1505arrow-down1imageThe inner fire of my hatred COULD melt steam beamsViking_Hippie@lemmy.dbzer0.com to Mildly Infuriating@lemmy.worldEnglish · edit-21 month agomessage-square51linkfedilinkfile-text
minus-squareozymandias117@lemmy.worldlinkfedilinkEnglisharrow-up4·1 month agoNIST’s official password guidelines state you should not have password expiry unless there is evidence of a compromise
minus-squareNewsteinleo@midwest.sociallinkfedilinkEnglisharrow-up1·1 month agoThat’s because they only read 800-63B and skip the other three documents.
minus-squareozymandias117@lemmy.worldlinkfedilinkEnglisharrow-up1·1 month agoThe majority of accounts I have don’t have an expiry I wouldn’t trust personal data with anything that does - they certainly don’t have any security professionals on staff
minus-squarebitchkat@lemmy.worldlinkfedilinkEnglisharrow-up1·1 month agoEvery job I’ve had in the past 10 years makes us reset passwords periodically
minus-squareNewsteinleo@midwest.sociallinkfedilinkEnglisharrow-up1·1 month agoMy last employer did not, life was so much better after the policy change. Although my director lost track of how long he had worked there because he stopped incrementing his password every three months.
minus-squareozymandias117@lemmy.worldlinkfedilinkEnglisharrow-up1·1 month ago10 years ago, that was believed to be best practice. If they’re still doing it in the last 2-3 years, they don’t have anyone keeping up with modern security standards At least it’s not your data
NIST’s official password guidelines state you should not have password expiry unless there is evidence of a compromise
And no one listens to that.
That’s because they only read 800-63B and skip the other three documents.
The majority of accounts I have don’t have an expiry
I wouldn’t trust personal data with anything that does - they certainly don’t have any security professionals on staff
Every job I’ve had in the past 10 years makes us reset passwords periodically
My last employer did not, life was so much better after the policy change. Although my director lost track of how long he had worked there because he stopped incrementing his password every three months.
10 years ago, that was believed to be best practice.
If they’re still doing it in the last 2-3 years, they don’t have anyone keeping up with modern security standards
At least it’s not your data