It took NIST 14 years to undo bad password rules — AI regulation may repeat the mistake

nptacek · x · 2026-09-14

IceSolst argues security theater backfires: mandatory 90-day password rotation pushed users to weaker passwords and took NIST 14 years to reverse. He warns today's 'AI safety experts' are repeating the pattern — clumsy AI regulation will drive shadow IT/AI use and make everyone less insecure, driven by regulators' own agendas rather than end-user safety.

Original post →

More from Safety

Safety channel →