4 ms·
I always wonder why employers don't just set passwords for their users and only give them the option to randomize them. Seems like an ideal solution, if using p
by pseufaux 3y ago
I always wonder why employers don't just set passwords for their users and only give them the option to randomize them. Seems like an ideal solution, if using passwords is a requirement.
- mewpmewp2 3y agoMaybe it would be fine if it was random 4 words like in the XKCD, but otherwise it would cause people to plaster sticky notes everywhere and hardcode it in their computers, no?
- reifyx 3y agoif you work from home, a sticky note with a strong password might be safer than a memorized employee-chosen password
- mewpmewp2 3y agoBut then imagine once in a while they have to go out to work, they might have to take this along with them and then both laptop and the sticky note together are vulnerable for either accidental theft or intentional.
- pseufaux 3y agoAgreed though I'd argue sticky notes happen even with user supplied passwords. When I worked at a university, I cannot tell you how often I found a sticky not on the bottom of a keyboard with a list of passwords.
- SAI_Peregrinus 3y agoRequiring SSO mostly does this, except for the SSO passphrase. That should be randomly generated, but usually isn't.
- playingalong 3y agoSome employers just buy a 1Password license for their staff.
- jbverschoor 3y agoYou still need a proper master password
- fzeroracer 3y agoThere's been more than a few times where I've been annoyed because a site or employer refuses to allow randomly generated passwords or allow me to copy/paste into the password field. I firmly believe the safest option is a local password manager with randomized passwords that you maintain local backups of.
- batch12 3y agoYou lose nonrepudiation if more than one person has knowledge of your employee's passwords. Typically, that's how it works though from what I've seen. An organization will set a users initial password and the user will have to change it on next login. There are some solutions that will look for known compromised hashes and weak combinations and alert on them or force the user to act, though.
- pseufaux 3y agoTrue, but why would the organization need to store the password? Wouldn't it be simpler to just generate a random 4 words (or something similar) then treat it the same as a user supplied one.
- akerl_ 3y agoThe better option for employers is to just get rid of passwords and move to something like FIDO2.
- kemotep 3y agoPasskeys are still very rough around the edges and not widely supported but a first-class onboarding and management experience for public key cryptography as account passwords a la FIDO2, webauthn, and/or Passkeys will be amazing for solving the issues with phishing and weak passwords.
- akerl_ 3y agoThis is generally way easier for employers, since they can pick a FIDO2-enabled SSO platform, and then tie everything to that. So you don’t need each service to have sane FIDO2 support, you just need them to support SAML/OIDC/etc. You also get mostly out of the key management business, because you can say “if you get locked out, call the help desk”, vs personal usage where backup keys / account recovery requires a per-service recovery flow.
- pseufaux 3y agoCompletely agree, at least in an idealistic scenario.