It's a great one. Not only does i recommend against composition rules, but
> Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)
Oh, if there is a sin against passwords it is forcing quickly memoizable (i.e. simpler) passwords.
password1 -> password2 -> password3
It's a great one. Not only does i recommend against composition rules, but
> Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)
Oh, if there is a sin against passwords it is forcing quickly memoizable (i.e. simpler) passwords.