DEV Community

Panda Quests
Panda Quests

Posted on

Does changing password frequently improve or harm security?

Top comments (3)

Collapse
 
nirenj profile image
Nirenj

According to NIST password policy (pages.nist.gov/800-63-3/sp800-63b....)

NIST SP 800-63B, Section 5.1.1.2 Memorized Secret Verifiers
“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”

Please also see here: jumpcloud.com/blog/nist-800-63-pas...

Collapse
 
pandaquests profile image
Panda Quests

Thanks. Useful information. I followed you and I am looking forward to see more post about it security in the future here

Collapse
 
pandaquests profile image
Panda Quests

I posted a question regarding password. (My latest question) can you have a look and give me your insights?