Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The company I work for had a ransomware issue, so they got more zealous about security.

They require us to change our passwords every 45 days now. When I pointed out the NIST recommendations of not rotating passwords, they say they are following the guidance of the response team that helped them recover from the ransomware. And that the NIST doesn't actually deal with the real world.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: