Why Mandatory Password Expirations Don T Make Sense Anymore
What Does Password Expiration Solve? First, it’s important to understand why enforced password expirations became popular. Most organizations require a password change every 30 or 90 days. This dates from the historical background of simpler password hashes which could be cracked relatively quickly. Back when an attacker could crack a password in a couple of months, security practitioners suggested that changes within that timeframe would help to keep users safe....