I always use very strong passwords, like "8UyTgFm,L;<kMkMkP-0O/", that are generated for me by the password manager I use. I never use the same password for more than one location.
The current password policy forcing me to change my password every 100 days (or whatever it is) is excessive and insulting. I participate in dozens of forums and I have accounts at several financial institutions, medical organizations, and online retailers. None of them require me to change my password at all -- ever. While I applaud your intention to minimize risk to your users, this policy is excessive, unnecessary, and pretty much non-existent elsewhere. If you insist on being an outlier, I suggest offering a bypass option. And I bet you have lost some subscribers because of the hassle to constantly change passwords.
The current password policy forcing me to change my password every 100 days (or whatever it is) is excessive and insulting. I participate in dozens of forums and I have accounts at several financial institutions, medical organizations, and online retailers. None of them require me to change my password at all -- ever. While I applaud your intention to minimize risk to your users, this policy is excessive, unnecessary, and pretty much non-existent elsewhere. If you insist on being an outlier, I suggest offering a bypass option. And I bet you have lost some subscribers because of the hassle to constantly change passwords.
Comment