@Tutanota Well, it depends. If you’re doing eCommerce, the PCI DSS v4.0 still requires regular password rotation (ok, with a maximum interval of 1year, but still) 😎
Top-level
@Tutanota Well, it depends. If you’re doing eCommerce, the PCI DSS v4.0 still requires regular password rotation (ok, with a maximum interval of 1year, but still) 😎 2 comments
@simonlevesque as the PCI DSS also requires MFA, so I do hope that should not be possible. |
@Linkshaender @Tutanota most likely for another reason: to ensure no one that was in a company and got the password can use it forever even when leaving the company