3 ms·
There are two major problems with standards. First, companies lie. I've been through a few companies that were audited for security compliance and simple trut
by cdumler 5y ago
There are two major problems with standards.
First, companies lie. I've been through a few companies that were audited for security compliance and simple truth was the company made great pains to keep the auditors away from but a few key people who will say what the auditors want to hear. Once, I was even told what I would need to say if I were asked (and it was blatantly untrue). Companies see security as a cost, not as an investment for on-going operations. So, the goal is to check it off the list that you're complying, not actually do it.
Second, best practices actually aren't. For instance, in my company I talked with the head of security after a presentation. I said that having passwords rotated was a horrible practice. It forces users to come up with something memorable. We should be using password managers and start using a long, random, gibberish passwords. He agreed, but "this is (such and such's) standard of best practices we contracted to support so we have to do this."
- jjav 5y agoOn the second point, thankfully we now have the NIST password guidelines recommending against password expiration, so we have an authoritative source to point at when fighting back against counterproductive password policies.