you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 3 years ago

I've had arguments with clients' IT security about this in the past where they demanded forced password resets. Citing NIST controls that insist you should avoid them was apparently insufficient.

  • source
  • parent