4 ms·
The 90 day password thing is pretty universal in my experience, but to be fair NIST has only very recently changed their recommendation on this so you can under
by herghost 10y ago
The 90 day password thing is pretty universal in my experience, but to be fair NIST has only very recently changed their recommendation on this so you can understand business' reticence to ease off on it.
As for the multiple internal sites and servers thing...well, from a security point of view I totally agree with the requirement for separate passwords but it sounds like you're in need of a proper identity management solution - which isn't really fair to blame security for - it's not usually the security function who are going to implement and own this sort of thing.
- ajford 10y agoI'm SO glad NIST put out that new recommendation. I really hate the whole 90 day thing. Argued for days (friendly argument) with one of my co-workers who was partly responsible for our implementation of the 90 day rule on how it wasn't necessarily better, and often lead to stupid passwords with very dumb/simple patterns. Even with the new NIST rec, I can't get him to back off on it, so sadly we'll be stuck on that for a while.
- user5994461 10y agoIt's only a DRAFT at the moment. It may take a while to be finished.
- herghost 10y agoMaybe 8-10 years ago there was a solution (an AD add-on/schema) I was looking at which set a password change frequency dependent on the password complexity - so a shitty 8 char, lowercase password would be acceptable but might be forced to change every 5 days. Drop a number and something uppercase in there and you might get 15/20 days. Drop a proper password and you might get 90-180 days. I really wish that had taken off (or, more accurately I guess, had a real business case). As an industry we tout one set of rules/principles but then enforce a slightly different version. My main passwords (the ones I have to remember, and not store) are all over 20 characters long and maximally complex and I change them very, very rarely.