Why does nobody talk about how password rules flipped in the other direction
Back when I started at a bank in Des Moines around 2012, our IT guy made everyone change passwords every 60 days with a symbol, a number, and two capitals. Now NIST says long passphrases beat all that, and my company dropped forced resets in 2023 after a security audit. Did the old rules actually make us safer, or were we just annoying ourselves for 10 years?
Man, those 60 day resets were the worst, people just did Password1! then Password2! and called it a day. Turns out the forced changes made folks pick weaker stuff they could remember, which is the opposite of safe. If your job still makes you rotate every few months, push back with the NIST thing, it actually holds up.