I was trying to understand how to maintain the work factor for passwords hashed with bcrypt.
I find a solution there: Optimal bcrypt factor, that's essentially saying that you can re-hash on the user login.
But I don't understand how it solves the problem for the users that don't login for a long time. In this case I suppose the only solution is to send them an email saying that their account will be desactivated for security purpose?