Comment by fragmede
11 hours ago
tokens yes, password rotation, no.
In 2017:
> NIST changed the guidance with SP 800-63B, published June 2017. It explicitly said:
"Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."
Instead, passwords should be changed when there is evidence they have been compromised, not every 30/60/90 days.
No comments yet
Contribute on Hacker News ↗