Skip to content

Instantly share code, notes, and snippets.

@shmup
Created December 2, 2025 20:45
Show Gist options
  • Select an option

  • Save shmup/a11878a0def97fd63a06b5b4376636d3 to your computer and use it in GitHub Desktop.

Select an option

Save shmup/a11878a0def97fd63a06b5b4376636d3 to your computer and use it in GitHub Desktop.
<friend> re: work making u change passwords, you should tell them they're going aginst NIST 800-63-4 section 3.1.1.2(6)
<friend> "Verifiers and CSPs SHALL NOT require users to change passwords periodically."
<friend> this is new recently
<friend> it changed from SHOULD to SHALL
<friend> no wiggle room now. if you're making people change passwords you are breakin da law
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment