Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you require PCI DSS compliance it won't fly either.

https://pcipolicyportal.com/blog/pci-compliance-password-req...



If you require PCI DSS I hope you're not just blindly following some random post on hackernews for your policy ;)


I'm not, that's why I know PCI DSS requirements off-hand.


No. You can use NIST guidance and are not required to change your password every 90 days




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: