Skip to content

Add recommendation for password expiration #18

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

bleetsheep
Copy link

As written in the recommendation, it has long not been best current practice anymore to force password changes upon users. Sources (as also referenced in the recommendation):

My thoughts on the matter are:

  • The warning "there are users without expiring passwords" should just not be shown in general because it's not a warning: it's a good thing.
  • However, many people still don't know this (both inside and especially outside the security field). It might be better to make people aware of updated research (for decades, "change your passwords" has been repeated and recommended, and many people know of the "change your password" day even if they don't do it).
  • Some organisations might want to see this warning because they have a policy diverging from the latest recommendations, so that's another reason to potentially leave this in (even if it seems misguided to me).

I'm fine just getting rid of WPC112 altogether if that's the course you prefer to steer, but recognizing that removal of a warning likely creates debate and that there are also reasons to keep it, adding pointers to research seems more practically useful.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant