5 ms·
Funny how there is a post-it with a password glued to the screen of the computer in the lede image, now in plain sight for thousands of readers.
by sirnonw 1y ago
Funny how there is a post-it with a password glued to the screen of the computer in the lede image, now in plain sight for thousands of readers.
- ashton314 1y agoLooks like there's a year at the end; might be to facilitate suckurity requirements such as yearly password rotation.
- ronsor 1y agoSome places do 3 months! It's amazing
- mystraline 1y agoPasswordAugust2025!
- Izkata 1y agoI keep a list of every time I change one of my work passwords with the date it would have expired, and it seems to fluctuate between 2.5 and 3.5 months with little consistency. Some of us used to have it locked so we didn't need to keep changing it, but they reenabled it some time ago and we got confirmation it was for some sort of external security requirements.
- bongodongobob 1y agoThat was best practice until maybe 10 years ago. Point the people in charge of that to the NIST standards.
- hdgvhicv 1y agoI hear cyber insurance companies (ransomware cover etc) still require outdated standards.
- bongodongobob 1y agoPeople think cyber insurance requirements are hard rules, but they aren't. For the most part, you just need to show effort as it's completely impossible to be 100% compliant with all standards. For example, if you weren't rotating passwords but had proper MFA on your accounts, you're fine. Hell they even have conflicting standards sometimes. I've been through this multiple times when I worked at an MSP. For the most part, leadership just pushes to meet those standards to cya, which makes sense, but as long as you don't demonstrate gross negligence, they'll pay out.
- deleted 1y ago[deleted]
- aaron695 1y ago[dead]
- downrightmike 1y agoMy guess: Ccjacs 2004 Odds are it hasn't been updated for 20+ years
- IncRnd 1y agoI think this is Ccjaas2004. I'm not 100% sure on the letters, but the year is easy to see. Hopefully, they've changed their password sometime in the past 21 years.
- deleted 1y ago[deleted]
- jchw 1y agoThat's true. Now it is most likely Ccjaas2025.
- IncRnd 1y agoI think you're correct. They probably use it as the password "format" and haven't updated the post-it in order to trick anyone trying to steal the password! What could go wrong?
- pmontra 1y agoThat's CCJ who married AAS in 2004. The password is still the same. But what's the username and what's the service?
- IncRnd 1y agoEverybody logs-in with the same username into the only app. It's a kiosk computer without a surviving vendor to support it.
- netsharc 1y agoThe image URL contains a parameter for size in pixel, and it's modifiable...
- Retr0id 1y agoIt's ok, comes back clean on https://haveibeenpwned.com/Passwords https://haveibeenpwned.com/Passwords, probably a few more years of life left in it!
- alephnerd 1y ago@Dang can you please delete this comment OP might not be wrong, but let's at least follow SOP for disclosing security failures (30 days pre-disclosure)
- idiotsecant 1y agoYou'd be surprised (or probably not) how much incredibly critical infrastructure has one ancient lynchpin PC doing some weird essential thing with a post-it note password like NameOfCompanyYear! where it's clear based on the year that the password hasn't been reset in a quarter century
- conorcleary 1y agoSorta how those Fox Raw livestreams on YouTube Live consistently show the inner workings of room-to-room shuffles and background whispers INSIDE the White House for the entire online world to dissect; it's definitely a security flaw but maybe not considered so by either Fox or the admin.