#5697 - Add admin tool for mass invalidating member passwords

This is a spacer post for a website comment topic. The content this topic relates to: #5697 - Add admin tool for mass invalidating member passwords
"Members who have not changed their password in X days or longer" - maybe, but most people hate this. https://pages.nist.gov/800-63-FAQ/#q-b05
The point of this tool is to invalidate passwords in the event of a breach. So that criterium is not actually for password expiration but rather manually invalidating passwords which have not been changed in a long while (in the event of a breach) as they are more likely to exist in brute-force rainbow tables.

Composr already has password expiration as a separate config option.

Ah, right.
0 guests and 0 members have recently viewed this.