• ozymandias117@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 day ago

    NIST’s official password guidelines state you should not have password expiry unless there is evidence of a compromise

      • ozymandias117@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        The majority of accounts I have don’t have an expiry

        I wouldn’t trust personal data with anything that does - they certainly don’t have any security professionals on staff

          • ozymandias117@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            10 hours ago

            10 years ago, that was believed to be best practice.

            If they’re still doing it in the last 2-3 years, they don’t have anyone keeping up with modern security standards

            At least it’s not your data

          • Newsteinleo@midwest.social
            link
            fedilink
            English
            arrow-up
            1
            ·
            23 hours ago

            My last employer did not, life was so much better after the policy change. Although my director lost track of how long he had worked there because he stopped incrementing his password every three months.