| ▲ | fragmede an hour ago | |
tokens yes, password rotation, no. In 2017: > NIST changed the guidance with SP 800-63B, published June 2017. It explicitly said: "Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)." Instead, passwords should be changed when there is evidence they have been compromised, not every 30/60/90 days. | ||