Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Absolutely. In the real world there's just no case for password expiration any more. Require at least 14 characters. Don't insist on any "complexity" rules, but do check passwords against a list of of common/stupid ones and reject them. Use a good hash algo, like bcrypt, scrypt, or Argon2


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: