Forcing a password change after a period of time has shown to make people gravitate towards the simplest passwords that are still within the policy or other, even less secure, solutions. That's why security standards nowadays advise to not implement forced password changes.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
replies: