Quote:
Originally Posted by brentbacardi
OH man i hate having to change passwords ever 90 days or whatever. They did a study where they show that changing your password ever X amount of days doesn't actually help.
"...particularly slams the common requirement that users change passwords at specified intervals. A hacker who steals your password is going to use it right away; he won't wait two months."
http://www.pcmag.com/article2/0,2817,2362692,00.asp
I think just having a good password and closing old accounts, or just verifying the email on old accounts would be best. When they make you change your password, people tend to write it down and stick it under their keyboards and that cannot be any better. 
|
Hi,
I meant to just reverify your email, not change passwords every 90 days. But, if someone were to hack and old gfy username that has not been used in over 90 days, then they could not use it unless they also hacked that gfy users email account, bcause once they try to login to the hacked gfy account, it will send a email verification to that gfy users email, and until clicked, that gfy username cannot login and be used.
I hate changing passwords too... so that's not what I meant.
~Ray