3 ms·
We had to delay rolling out one of the more recent Mac OS releases (Catalina, maybe) because it used the more secure “encrypt the data and throw away the key” i
by neurobashing 6y ago
We had to delay rolling out one of the more recent Mac OS releases (Catalina, maybe) because it used the more secure “encrypt the data and throw away the key” instead of “write 0 to the sector 5 times” secure delete thing. Microsoft did research on how bad password rotation is, but it’s still the rule. Regs that can’t keep up with the pace of the thing they’re regulating are as bad as none at all, I think.
- CyanLite4 6y agoNIST finally jumped on the “long passwords are stupid and password rotations are for suckers” bandwagon about 3 years ago. Problem is PCI, HIPAA and others haven’t changed their rules to accommodate. However, auditors aren’t stupid. I’ve told mine, “here, look at the new NIST standard” and they say “okay, yea MFA is better”. As long as you can point to their technology standards agency (NIST, FIPS, DISA, etc) you should be good to go.
- whydoyoucare 6y agoThis has been my experience too. Typically, standard bodies move at a different pace, and as long as you use a reputable known standard, you're good to go.