4 ms·
Too bad it won't get adopted by existing systems. I know huge companies still doing mandatory frequent password changes despite us telling them it goes against
by throwaway984393 2y ago
Too bad it won't get adopted by existing systems. I know huge companies still doing mandatory frequent password changes despite us telling them it goes against NIST for years.
- kelnos 2y agoYep. The bit about not doing mandatory periodic password resets has been in these recommendations for a while, but most companies I hear about still require them.
- JimDabell 2y agoI still see bullshit like this from pen testers, who really should know better.
- _dain_ 2y agoWho? Name and shame them.
- JimDabell 2y agoQuite honestly, I can’t think of any that don’t give bad advice on passwords. It seems to be pretty universal that they aren’t aware of best practice and cargo-cult the bullshit instead.
- JambalayaJimbo 2y agoA lot of pen testing companies are glorified but box checkers. I’ve submitted many applications with glaring security holes in them to pen testing and never heard a peep.
- snorremd 2y agoThis! Required frequent changes just makes people who don't use password managers choose weaker passwords to be able to remember them easily. And they'll almost guaranteed just choose the same password as before with a new post or prefix. "mychildhoodteacher1", "mychildhoodteacher2", etc. It would be better to encourage users to use a single random four word passphrase and stick to that forever. Add 2FA and you are golden. But legacy systems gonna legacy. I still see systems with max password lengths of 12 characters in the wild, and no 2FA to boot. It's been a while since I got my password back in clear text though, so perhaps we're moving in the right direction.