Challenging the Conventional Wisdom on Mandatory Password Changes

Very interesting thought piece from the FTC’s Chief Technologist. Do mandatory password resets actually make us less secure?  Not necessarily, but they could, if we do not train users to be aware of the subconscious pitfalls.

