PSA: that 'change your password every 90 days' rule is finally dead, and the reason is funny
Found out from a NIST writeup that forced 90 day password swaps made people pick stuff like Summer2024! and just bump the number, so the new rule is only change it if there's a real breach, and honestly my old job in Tampa made us rotate every 60 days which was even worse.