Never Change Your Password - TidBITS
Many websites advise you to change your password routinely. That advice is nearly universally wrong: you should only update a password when there’s a weakness. Why does it persist?
I’m going to set off all your smoke alarms when I make this fiery statement: Never change your password. Before you call the fire department, consider these three crucial provisos. Never change your password… If it’s sufficiently strong If you created a unique one for each account Unless there’s a security breach where it’s stored Passwords do not age. They do not sour, spoil, or go stale. Yet some organizations want to convince us that your passwords become increasingly susceptible to attack over time. Just yesterday, I logged into my T-Mobile account and was told my password was old and shou
related reading
- Digital hygiene – karpathykarpathy.bearblog.dev
- The Letter - Stop Hacklore!hacklore.org
- Andrej Karpathy on X: "I wrote a quick new post on "Digital Hygiene". Basically there are some no-brainer decisions you can make in your life to dramatically improve the privacy and security of your computing and this post goes over some of them. Blog post link in the reply, but copy pasting below https://t.co/gRyeVouko5" / Xx.com
- Apple ‘passkeys’ could finally kill off the password for goodtechcrunch.com
- Practical Advice to Avoid Getting Pwned by AIchoosingvictory.com
- This Page is Designed to Last: A Manifesto for Preserving Content on the Webjeffhuang.com
- 資安最前線》無密碼的數位世代,行嗎? | 遠見雜誌gvm.com.tw
- sec22-pal.pdfusenix.org
- Why We Don’t Trust the Database With Authentication – Sturdy Statisticsblog.sturdystatistics.com
- Things You Should Never Do, Part I – Joel on Softwarejoelonsoftware.com
- App Developers: Start with Securityftc.gov
- How Apple and Amazon Security Flaws Led to My Epic Hacking | WIREDwired.com