Changing your password every 90 days is outdated advice

For years, IT departments have drilled the 90-day password change rule into our heads, and most of us never questioned it. The logic seemed sound when computing power was more limited and cracking a password hash took considerable time. The rule was to change your password regularly and stay secure. However, security experts, including NIST, have moved on from this advice, and modern alternatives like passkeys are making passwords obsolete.



via MakeUseOf https://ift.tt/BL6yTMe

Comments