Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

NIST has a standard(s?) that says password strength rules are dumb and regular rotation is not necessary. Great, except we all know both are still widespread even by US sites. There's no 'oi comply with the NIST standard' regulation (for most companies anyway).


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: