Suspended
- Join Date:
- Jun 2007
- Location:
- Eustis, Florida, USA, EARTH
- Posts:
- 868
- Plugin Contributions:
- 0
Yubikey to replace 90 day password changes
Changing passwords every 90 days is absurd. If places like amazon dont require us to do it why should ZC? There are much more better options to harden servers than changing passwords every 90 days. Servers without firewalls or modsecurity enabled would be compromised with or without changing passwords every 90 days.
I would like to see us to have the option of using Yubikey (or Googles Titan) instead of changing all of our passwords every 90 days. I have more than a dozen websites all with staggered 90 day expirations. Crazy and aggravating. Magento shopping cart doesnt have any such requirements and they are owned by ebay.
Its time to throw away this archaic method of hardening servers, even if it means using a password that is a sentence instead of a word.
