top | item 30557192

(no title)

Zxian | 4 years ago

The intent of the policy doesn't match the real-world implementation of users. Users are lazy. Users will alter a single character or digit in the password and call it changed.

Most people don't use password managers, and some companies block their usage. Now add a requirement of a "secure" password.

discuss

order

nixpulvis|4 years ago

Automated password rotation would use machine generated highly secure passwords. I do not see your point.

This issue for master passwords is a bit harder, yes.

Sohcahtoa82|4 years ago

> Automated password rotation would use machine generated highly secure passwords.

Which will result in two things:

1. LOTS of calls to IT from forgotten passwords

2. People writing their passwords down on sticky notes.

the_snooze|4 years ago

If you're using machine-generated passwords, then what's the point of rotating them?