3 ms·
>I'm still rotating password A bit off-topic, but I find this crazy. In basically every ecosystem now, you have to specifically go out of your way to turn on m
by jfindper 10mo ago
>I'm still rotating password
A bit off-topic, but I find this crazy. In basically every ecosystem now, you have to specifically go out of your way to turn on mandatory rotation.
It's been almost a decade since it's been explicitly advised against in every cybersec standard. Almost two since we've done the research to show how ill-advised mandatory rotations are.
- mwigdahl 10mo agoBut that would mean doing less, and that's by default bad. We must take action! Think of the children! I tried at my workplace to get them to stop mandatory rotation when that research came out. My request was shot down without any attempt at justification. I don't know if it's fear of liability or if the cyber insurers are requiring it, but by gum we're going to rotate passwords until the sun burns out.
- mboerwink 10mo agoPCI still recommends 90 day password changes. Luckily they've softened their stance to allow zero-trust to be used instead. They're not really equivalent controls, but clearly laid out as 'OR' in 8.3.9 regardless.
- jfindper 10mo agoI think it's only a requirement if passwords are the sole factor, correct? Any other factor or zero-trust or risk-based authentication exempts you from the rotation. It's been awhile since I've looked at anything PCI. In any case, all my homies hate PCI.
- deleted 10mo ago[deleted]