Warning: Some posts on this platform may contain adult material intended for mature audiences only. Viewer discretion is advised. By clicking ‘Continue’, you confirm that you are 18 years or older and consent to viewing explicit content.
Yes, password expiry is generally considered bad practice and should only be triggered on demand if there’s suspicion of a security breach, precisely because it’s much more likely to lead to simple, less secure passwords. And when users change it, they will probably just add a number or something anyway, so it’s not going to stop a determined attacker from finding the new pw regardless.
Which doesn’t stop a ton of organizations from requiring it anyway.
Yes, password expiry is generally considered bad practice and should only be triggered on demand if there’s suspicion of a security breach, precisely because it’s much more likely to lead to simple, less secure passwords. And when users change it, they will probably just add a number or something anyway, so it’s not going to stop a determined attacker from finding the new pw regardless.
Which doesn’t stop a ton of organizations from requiring it anyway.