Hacker News new | past | comments | ask | show | jobs | submit login

> Passwords should be regularly rotated

Disagree. I'd even call required rotation a smell.

Requiring rotation leads to people coming up with passwords more frequently, meaning they'll likely choose weaker passwords. On top of that, regular rotation isn't necessary for passwords generated independently by a password manager.

The issue here is that there's no way to deal with revocation / password changes if a service is compromised.




It doesn't matter what you think. If someone's using a service that requires it and the tool doesn't allow it it's no good.


I responded to that in the original comment. Whether or not a service requires rotation (bad practice), this tool won't work (can't handle compromised passwords).




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: