9
jkuhl
1y

If I have to change my domain password every 3 months for a bullshit out of date security policy (there's plenty of evidence suggesting that changing passwords is actually worse security), then maybe, just FUCKING maybe, make sure that that password change appropriately filters down to things like SQL Server so I can keep doing my goddamn work.

Comments
  • 0
    Why is changing password frequently bad for security? Could you elaborate
    that please?
  • 5
    @tonypolik if it's a password that you need to remember yourself, you need to make it simpler to accommodate the fact that you need to remember a new password every three months.
  • 1
    try tricking administration into giving you a temporary password. then use that forever since those usually don't need to change.

    also: password managers.
  • 1
    Last time I had to periodically change my password, I just named 3 things I could see. Hello "StaplerCloudWindow". Stupid rule.
  • 0
    @tonypolik the more complex a password, the more secure it is. However if it's a password you actually need to type in, you'll have a hard time remembering it. If there's a policy to change the password every so often, people will tend to try and use simpler passwords, or (especially in company IT settings) take note of their password in places very close to their PCs.
  • 0
    I never have to remember a password because i use password manager such as keepass
  • 0
    The idea behind regularly PW changes is, while a bruteforce attack is going on, you change the PW so they have to start from the top. Novel idea, but hopelessly outdated (2FA/MFA, rate limitations, fail-to-ban, etc.).

    In combination with a PW policy, people will use less complex PWs (instead of a PW manager).

    PW managers don't work for BIOS or Bitlocker. Also you need a master PW for the PW manager. And then ppl want to share PWs when the person in charge takes their vacation. And you can have multiple PW managers. And multiple Authenticator apps (Google + Microsoft + some no-name crap who build their own standard).
    And as a dev, I would like to disable authentication on the app I'm just working on locally...
  • 0
    @SuspiciousBug novel but outdated 🤔
  • 0
    @electrineer for your everyday website, yes. Ever logged in to Google on a new device? MFA all the way
Add Comment