4 ms·
I suspect they want to be able to brute-force passwords if they really need to, in the event of a uncooperative or malicious employee, and these rules allow for
by aaronchall 7y ago
I suspect they want to be able to brute-force passwords if they really need to, in the event of a uncooperative or malicious employee, and these rules allow for that.
- yjftsjthsd-h 7y agoWhy would you ever need that? If you have administrator access, just perform whatever the local equivalent of `su` is.
- carterehsmith 7y agoUm... if "they" are system administrators, they do not need to brute-force password. They can just change it to whatever they want.
- ineedasername 7y agoNah, they tend to be systems whose original infrastructure was written pre-internet and had 3 or 4 (or more) decades of bolt-ons laid on top. Password security wasn't nearly as much of an issue, but now the same system that had been designed for employee use now is used by customers and is exposed to the web. Kind of like taking a lock on a diary meant to prevent casual perusal by a sibling and puting it on a bank vault because you put the diary in the vault.