Educause Security Discussion mailing list archives

Re: Current Best Practice regarding Password Change policy


From: "Scott O. Bradner" <sob () HARVARD EDU>
Date: Fri, 24 Sep 2010 09:20:50 -0400

We currently require all, Students, Faculty and Staff, to change passwords
every 90 days

I think this is counterproductive and reduces security

see http://www.cerias.purdue.edu/site/blog/post/password-change-myths/

Scott


Current thread: