Baldwin Consulting Services, LLC

Continuity Management and Technology Services – News Reblog

Password1, Password2, Password3 no more: Microsoft drops password expiration rec – Ars Technica

The rationale for the previous policy is that it limits the impact a stolen password can have—a stolen password will automatically become invalid after, at most, 60 days. In reality, however, password expiration tends to make systems less safe, not more, because computer users don’t like picking or remembering new passwords. Instead, they’ll do something like pick a simple password and then increment a number on the end of the password, making it easy to “generate” a new password whenever they’re forced to.

Link