In May, Microsoft removed from Windows 10 the technology that forced users to come up with new passwords after a certain period. This has finally come to an end! In Redmond, official security requirements were updated in response to evidence that such an approach does not improve, but rather weakens security.

In Windows 10 (1903) and the server version of the 'ten', users can now set a single password and not count the days until it needs to be changed. As noted in a piece by TechCrunch, regular password changes are counterproductive. This is also affirmed by the software giant.
The essence is that if a password is stolen, such a scheme does not allow for immediate changes — one has to wait until the term expires. If the password hasn’t been stolen, there’s no need for a change. As an alternative, multi-factor authentication, tracking attacks on internal resources, and biometrics are proposed. Regular password changes have simply been labeled an outdated and irrelevant method of protection. It is also recommended to use password managers, such as LastPass or 1Password, and to send codes via SMS.
Microsoft notes that perfect security does not exist (unless the PC is turned off, disconnected from the network, and in a safe), but a sufficient level of security can be easily ensured. One just needs to follow a few simple rules.
It is worth noting that the company from Redmond clung to the practice of regular password changes for a long time, so its calls to stop using this technology seem especially ironic. Although it has indeed become outdated.
Source: 3dnews.ru
