4 ms·
The most hilarious rules I've encountered were for a large, well known US hospital: * Password must be EXACTLY 8 characters long * Password must start with a
by Thriptic 7y ago
The most hilarious rules I've encountered were for a large, well known US hospital:
* Password must be EXACTLY 8 characters long
* Password must start with a letter
* You must use exactly 3/4 of the following: upper case, lower case, numbers, one of three special characters
* Password cannot "resemble" username or past password
- txcwpalpha 7y agoSounds like they were using z/OS or RACF [1] mainframe as a backend. Oof. Unfortunately, it's not that uncommon. I've done security consulting work at a few major F500 companies that were using this and had those same password rules. At one of them, it got to the point where almost every security review meeting had to start with "yes yes we already know how bad the password are, don't bring it up, let's talk about something else". 1: https://www.ibm.com/support/knowledgecenter/en/SSLTBW_2.1.0/com.ibm.zos.v2r1.icha100/pass.htm https://www.ibm.com/support/knowledgecenter/en/SSLTBW_2.1.0/...
- aaronchall 7y agoI suspect they want to be able to brute-force passwords if they really need to, in the event of a uncooperative or malicious employee, and these rules allow for that.
- yjftsjthsd-h 7y agoWhy would you ever need that? If you have administrator access, just perform whatever the local equivalent of `su` is.
- carterehsmith 7y agoUm... if "they" are system administrators, they do not need to brute-force password. They can just change it to whatever they want.
- ineedasername 7y agoNah, they tend to be systems whose original infrastructure was written pre-internet and had 3 or 4 (or more) decades of bolt-ons laid on top. Password security wasn't nearly as much of an issue, but now the same system that had been designed for employee use now is used by customers and is exposed to the web. Kind of like taking a lock on a diary meant to prevent casual perusal by a sibling and puting it on a bank vault because you put the diary in the vault.
- colek42 7y agoStill no excuse. They need to create a custom encoding that works with their backend that allows more flexibility is password choice. It is not that tough of a problem.
- nulbyte 7y ago> They need to create a custom encoding... IBM already has solutions for secure passwords of variable length. Outdated systems may have stored passwords as plaintext with symbol limitations, but modern RACF can hash passwords, encrypt profiles, and generally take whatever you throw at it and handle it securely. The tech isn't the problem, only the personnel.
- yellowapple 7y agoThe "password must be exactly 8 characters" rule screams AS/400.
- ineedasername 7y agoI worked on a VMS system that used 4. It was originally meant to be a PIN entered over the phone, then the internet came along and that interface was exposed to the web. But it's okay, after a few years they upgraded to 6.
- iamnotacrook 7y ago"Password cannot "resemble" username or past password" So they're storing passwords in plaintext somewhere then? Otherwise how would they know?
- saint_abroad 7y agoPast passwords can be tested against past hashes.
- iamnotacrook 7y agoNot resemblance though surely, only an exact match.