4 ms·
I worked on Identity, Credentialing and Access Management (ICAM as it's known) in the Federal space for a while. The U.S. Fed Gov has been implementing MFA wit
by rterrin 5y ago
I worked on Identity, Credentialing and Access Management (ICAM as it's known) in the Federal space for a while.
The U.S. Fed Gov has been implementing MFA with smart cards since 2001. While there are pockets of ineptitude and resistance, the vast majority of government employees and contractors use a hard token second factor.
Security is a property of a system, so analyzing a particular password policy outside of the given context (mandatory hard token MFA) is nonsense.
- e1g 5y agoYes, and the latest Zero-Trust guidance is actually legitimately good - it enforces a security practice on all gov agencies that will be better than 99% of the private sector. The password policy is just one line, but still a welcomed slap on the face of all Old Guard folks (who are overrepresented in infosec policy-making). The rule is clear: MFA or GTFO.
- tempnow987 5y agoAnd with physical MFA you can get down to PIN level (ie, 6 digits) and you are beating 90% of other methods.