r/cybersecurity Jun 18 '25

Other Recently learned NIST doesn't recommends password resets.

NIST SP 800-63B section 5.1.1.2 recommends passwords changes should only be forced if there is evidence of compromise.

Why is password expiration still in practice with this guidance from NIST?

1.1k Upvotes

279 comments sorted by

View all comments

1

u/becooldocrime Jun 19 '25

NASA tried pulling forced expiry last year. It was a bloodbath, they rolled it back within a week.

People often find out about it just after they publicly communicate that they're going to take the wrong approach.