NIST Special Publication 800-63B - Digital Identity Guidelines "Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator."
The internet is ‘ok’
So that means we’re on a journey away from the PSN.
From F to A+: Getting Good Grades on Website Security Evaluations
If you’re ok with an A, use cloudflare. If you really want that A+, you can follow this post.
