There can be a useful communication of "passwords older than X should be changed" to the user. Blocking that doesn't make the user any worse off than simply not having it.
(That leaves the question of how useful it is to users; I guess it is nice for a service like lastpass, but the truly paranoid probably aren't relying on cues from services)
Comments
There can be a useful communication of "passwords older than X should be changed" to the user. Blocking that doesn't make the user any worse off than simply not having it.
(That leaves the question of how useful it is to users; I guess it is nice for a service like lastpass, but the truly paranoid probably aren't relying on cues from services)