Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Wed, 20 Apr 2016 23:55:19 +0200
From: "e@...tmx.net" <e@...tmx.net>
To: passwords@...ts.openwall.com
Subject: Re: Mandatory password changes - DIEDIEDIE!

On 04/20/2016 11:40 PM, Per Thorsheim wrote:
> Den 20.04.2016 22.57, skrev e@...tmx.net:
>>> The statement will simply be something like "stop changing passwords
>>> frequently".
>>
>> +1
>>
>>> We can no longer require users to have long & complex passwords, unique
>>> to every service & site, and additionally ask them to change them every
>>> 30-60-90 days.
>>
>> it is important to separate all these 4 points.

all i want to say is that my issue is with the phrase itself.
it can me read as if these (length, complexity, uniqueness, and 
expiration) are in some sort of balance together -- which is false -- 
they are completely independent.

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.