coates’s avatarcoates’s Twitter Archive—№ 20,173

  1. NIST on why your password policy is wrong. "Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)."