
NIST Recommendations Against Mandatory Password Resets
CybersecurityPassword PoliciesNIST GuidelinesSecurity Practices
Recently learned NIST doesn't recommend password resets. The post mentions that NIST SP 800-63B section 5.1.1.2 recommends that password changes should only be forced if there is evidence of compromise. The author wonders why password expiration is still in practice despite this recommendation from NIST.