4 ms·
Not mentioned in the article, but I bet seasonal/time-related passwords are due to password rotation policies. I work for a company too slow or stupid to have u
by rollulus 3y ago
Not mentioned in the article, but I bet seasonal/time-related passwords are due to password rotation policies. I work for a company too slow or stupid to have understood how counterproductive such policy is, and all my passwords are an update of the former. Because we humans cannot remember multiple strong passwords.
- Brajeshwar 3y agoAll of my Bank passwords are variations of Swear Words!
- mooreds 3y agoYes, NIST changed their guidance to advise against password rotation for this exact reason. I think the answer is distributed password managers, myself.
- rvnx 3y agoIt’s not necessarily management. When you run large IT systems, external auditors come into your systems and say : 1) no password rotation = bad 2) no password format enforcement = bad Though it’s absurd to force people to have a password between 6 and 8 chars for example, because it limits the amount of possibilities.
- bongodongobob 3y agoNo, password rotation has not been standard best practice for quite some time now. Best practice is long passwords with no rotation. For humans. Service/admin accounts should be rotating constantly.
- rvnx 3y agoApparently EY or KPMG are not aware of that, yet they make the rules
- instagib 3y agoWe had a randomly rotating admin position for security theater and network admin to keep things separate. Legally you can save passwords on the most secure network and realistically only remember one password. You have to memorize a lot of passwords otherwise. No phones. The NSA password reset questionnaire is hilariously a great life memory quiz. Almost everyone needs to reset some passwords daily even though we had the phone number keypads with special characters around. How to remember passwords was a routine conversation because certain systems had admin passwords to remember or passwords that would change at odd intervals or single account multiple user passwords. It came down to “how long after a password reset do you actually need to change the password? Does it check for past passwords?” There were passwords written down in not so secret places because the admin would not always be at work. Eventually we had to adopt token authorization which is a mess to implement also. I loved the security meetings only to discuss how screwed we were once they started enforcing policies.