> When good behavior is not forthcoming
The only bad behaviour, not that I'd choose that terminology, I'm aware of was password reuse. What was bad on their side?
The only bad behaviour, not that I'd choose that terminology, I'm aware of was password reuse. What was bad on their side?
Good behavior:
> The new NIST recommendations mean that every time a user gives you a password, it’s your responsibility as a developer to check their password against a list of breached passwords and prevent the user from using a previously breached password.
SP 800-63 specifically: https://pages.nist.gov/800-63-3/ | https://pages.nist.gov/800-63-4/