-
Notifications
You must be signed in to change notification settings - Fork 4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update: Authentication_Cheat_Sheet.md #1520
Comments
NIST suggests that the only time to rotate passwords is in the case of password data being compromised. So I suggest: Avoid requiring periodic password changes; instead, encourage users to pick a strong passwords and enable MFA. Consider password rotation only in case of compromise or when authenticator technology is changed. |
Hi @jmanico, could you please assign this issue to me? I'd like to take ownership and resolve it |
@jmanico ? |
All set, thank you @szh |
What is missing or needs to be updated?
The current Authentication page is not aligned with:
Some good quotes:
How should this be resolved?
This line does not make sense:
Password leak occurs all the time, and we do not want to force people to change their (potentially) good password for a new (potentially) bad password. Instead we should "annoy" the user with 2FA/MFA, tell them to use a password manager, etc
Suggestion for a new phrasing:
The text was updated successfully, but these errors were encountered: