"Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."
-NIST Digital Identity Guidelines Section 5.1.1.2

Yet I cannot escape IT departments insisting upon it. Every time it happens I want to send them a "cybersecurity training module" right back at them.

pages.nist.gov/800-63-3/sp800-

#cybersecurity

Follow

@dpthorngren lol. I have had this in my email signature for a couple years at work

Sign in to participate in the conversation
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.