Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I disagree. I feel it's not a site's responsibility to stop users from reusing their passwords if they choose to. It has no relation to the security of the service. As a metaphor, a good lock maker protects their customers from lock picking, not from a key left under the mat.

Personally, I reuse a simple password for very non-important services and it's very convenient. I think that's ok, or at the very least I should be able to choose to.



I've never heard of a website implementing something like this. Password rotation requirements are usually found in corporate or government settings, for logging into your workstation, email and internal applications.


"internal" and line of business apps are not provided as cloud hosted SaaS yet?

I work on a web based SaaS used mainly by different parts of the government and we are often asked about password policies and rotation, to which we point at the nist & nscs advice




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: