▲ 1478 ▼ Incorrect password (i.imgur.com) submitted 3 years ago by TheGoldenGod@lemmy.world to c/memes@lemmy.ml 97 comments fedilink hide all child comments
[+] Soundhole@lemm.ee 16 points 3 years ago* (last edited 2 years ago) (10 children) [deleted] permalink fedilink source hideshow 10 child comments replies: [–] pineapplelover@lemm.ee 22 points 3 years ago (8 children) Or use a fucking password manager like Bitwarden or Keepass permalink fedilink source parent hideshow 8 child comments replies: [–] Gormadt@lemmy.blahaj.zone 9 points 3 years ago (5 children) I won't say where I work but we have strict password requirements including that they have to be exactly 8 characters long. Yeah our passwords aren't very secure as we also have to change them every 90 days and if you miss the window by 3 days you have to call the IT desk to reset it which takes about 45 minutes to an hour. And in that time you basically can't get anything done. At home I use a password manager and all my passwords are randomly generated and whenever possible 2fa is enabled. permalink fedilink source parent hideshow 5 child comments replies: [–] Trapping5341@lemmy.world 11 points 3 years ago Personally I would use a password manager for at work as well. Bitwarden can generate 8 character passwords. Easy enough to remember and if you forget it's right there on your phone. permalink fedilink source parent [–] abraxas@lemmy.ml 7 points 3 years ago Not sure if you're in the US. But if you are, you should leave this anonymously on the security team's desks. > Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator. - NIST control SP 800-63B Section 5.1.1.2 Basically a fairly widespread standard of security. All kinda of complaince you can fall out of if you do business with anyone who cares about NIST controls. permalink fedilink source parent [–] TheMauveAvenger@lemmy.world 3 points 3 years ago (1 child) Get as many people as you can to change their password on or around the same day. 93 days later either bombard IT with simultaneous requests or maybe stagger them to eat up their resources for days. permalink fedilink source parent hideshow 1 child comment replies: [–] Gormadt@lemmy.blahaj.zone 2 points 3 years ago Pretty much how it is really, we also make sure to line it up when we return from holidays. Fun fact about our system, if you change you password on your own it restarts the clock from that day. permalink fedilink source parent [–] pineapplelover@lemm.ee 2 points 3 years ago This is the proper way to do things (on your end, not the 8 character password at work). I also use email aliases from simplelogin in addition to strong and unique passwords. So any data breach from a site should be isolated. permalink fedilink source parent [–] codapine@lemm.ee 1 point 3 years ago* (last edited 3 years ago) I use bitwarden on my android phone and home computer. Vivaldi browser on both devices with bw integration. I also was able to portable-load Vivaldi on my work pc, so one day when I'm not too busy, I intend to regen my work passwords (everything but the domain logon is web-based) with bitwarden so I never have to worry about how many ones and exclamation points I appended to my passwords. Now if I could only get them to replace Microsoft 365 OTPs with a smart card or RSA hardware token that'd be perfect. Especially when Teams and every other Microsoft app separately and individually decides for the nth time this week that they all need my credentials again because somebody sneezed near the work VPN server and caused the ntp to be off by a millisecond and invalidate my security certificate or... whatever the reason that happens. permalink fedilink source parent [–] abraxas@lemmy.ml 0 points 3 years ago I do. This still happens to me regularly. Companies love to fuck with their password algorithms way too much. permalink fedilink source parent [–] Sharkwellington@lemmy.one 4 points 3 years ago Brb stealing your cookies. permalink fedilink source parent
[–] pineapplelover@lemm.ee 22 points 3 years ago (8 children) Or use a fucking password manager like Bitwarden or Keepass permalink fedilink source parent hideshow 8 child comments replies: [–] Gormadt@lemmy.blahaj.zone 9 points 3 years ago (5 children) I won't say where I work but we have strict password requirements including that they have to be exactly 8 characters long. Yeah our passwords aren't very secure as we also have to change them every 90 days and if you miss the window by 3 days you have to call the IT desk to reset it which takes about 45 minutes to an hour. And in that time you basically can't get anything done. At home I use a password manager and all my passwords are randomly generated and whenever possible 2fa is enabled. permalink fedilink source parent hideshow 5 child comments replies: [–] Trapping5341@lemmy.world 11 points 3 years ago Personally I would use a password manager for at work as well. Bitwarden can generate 8 character passwords. Easy enough to remember and if you forget it's right there on your phone. permalink fedilink source parent [–] abraxas@lemmy.ml 7 points 3 years ago Not sure if you're in the US. But if you are, you should leave this anonymously on the security team's desks. > Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator. - NIST control SP 800-63B Section 5.1.1.2 Basically a fairly widespread standard of security. All kinda of complaince you can fall out of if you do business with anyone who cares about NIST controls. permalink fedilink source parent [–] TheMauveAvenger@lemmy.world 3 points 3 years ago (1 child) Get as many people as you can to change their password on or around the same day. 93 days later either bombard IT with simultaneous requests or maybe stagger them to eat up their resources for days. permalink fedilink source parent hideshow 1 child comment replies: [–] Gormadt@lemmy.blahaj.zone 2 points 3 years ago Pretty much how it is really, we also make sure to line it up when we return from holidays. Fun fact about our system, if you change you password on your own it restarts the clock from that day. permalink fedilink source parent [–] pineapplelover@lemm.ee 2 points 3 years ago This is the proper way to do things (on your end, not the 8 character password at work). I also use email aliases from simplelogin in addition to strong and unique passwords. So any data breach from a site should be isolated. permalink fedilink source parent [–] codapine@lemm.ee 1 point 3 years ago* (last edited 3 years ago) I use bitwarden on my android phone and home computer. Vivaldi browser on both devices with bw integration. I also was able to portable-load Vivaldi on my work pc, so one day when I'm not too busy, I intend to regen my work passwords (everything but the domain logon is web-based) with bitwarden so I never have to worry about how many ones and exclamation points I appended to my passwords. Now if I could only get them to replace Microsoft 365 OTPs with a smart card or RSA hardware token that'd be perfect. Especially when Teams and every other Microsoft app separately and individually decides for the nth time this week that they all need my credentials again because somebody sneezed near the work VPN server and caused the ntp to be off by a millisecond and invalidate my security certificate or... whatever the reason that happens. permalink fedilink source parent [–] abraxas@lemmy.ml 0 points 3 years ago I do. This still happens to me regularly. Companies love to fuck with their password algorithms way too much. permalink fedilink source parent
[–] Gormadt@lemmy.blahaj.zone 9 points 3 years ago (5 children) I won't say where I work but we have strict password requirements including that they have to be exactly 8 characters long. Yeah our passwords aren't very secure as we also have to change them every 90 days and if you miss the window by 3 days you have to call the IT desk to reset it which takes about 45 minutes to an hour. And in that time you basically can't get anything done. At home I use a password manager and all my passwords are randomly generated and whenever possible 2fa is enabled. permalink fedilink source parent hideshow 5 child comments replies: [–] Trapping5341@lemmy.world 11 points 3 years ago Personally I would use a password manager for at work as well. Bitwarden can generate 8 character passwords. Easy enough to remember and if you forget it's right there on your phone. permalink fedilink source parent [–] abraxas@lemmy.ml 7 points 3 years ago Not sure if you're in the US. But if you are, you should leave this anonymously on the security team's desks. > Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator. - NIST control SP 800-63B Section 5.1.1.2 Basically a fairly widespread standard of security. All kinda of complaince you can fall out of if you do business with anyone who cares about NIST controls. permalink fedilink source parent [–] TheMauveAvenger@lemmy.world 3 points 3 years ago (1 child) Get as many people as you can to change their password on or around the same day. 93 days later either bombard IT with simultaneous requests or maybe stagger them to eat up their resources for days. permalink fedilink source parent hideshow 1 child comment replies: [–] Gormadt@lemmy.blahaj.zone 2 points 3 years ago Pretty much how it is really, we also make sure to line it up when we return from holidays. Fun fact about our system, if you change you password on your own it restarts the clock from that day. permalink fedilink source parent [–] pineapplelover@lemm.ee 2 points 3 years ago This is the proper way to do things (on your end, not the 8 character password at work). I also use email aliases from simplelogin in addition to strong and unique passwords. So any data breach from a site should be isolated. permalink fedilink source parent
[–] Trapping5341@lemmy.world 11 points 3 years ago Personally I would use a password manager for at work as well. Bitwarden can generate 8 character passwords. Easy enough to remember and if you forget it's right there on your phone. permalink fedilink source parent
[–] abraxas@lemmy.ml 7 points 3 years ago Not sure if you're in the US. But if you are, you should leave this anonymously on the security team's desks. > Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator. - NIST control SP 800-63B Section 5.1.1.2 Basically a fairly widespread standard of security. All kinda of complaince you can fall out of if you do business with anyone who cares about NIST controls. permalink fedilink source parent
[–] TheMauveAvenger@lemmy.world 3 points 3 years ago (1 child) Get as many people as you can to change their password on or around the same day. 93 days later either bombard IT with simultaneous requests or maybe stagger them to eat up their resources for days. permalink fedilink source parent hideshow 1 child comment replies: [–] Gormadt@lemmy.blahaj.zone 2 points 3 years ago Pretty much how it is really, we also make sure to line it up when we return from holidays. Fun fact about our system, if you change you password on your own it restarts the clock from that day. permalink fedilink source parent
[–] Gormadt@lemmy.blahaj.zone 2 points 3 years ago Pretty much how it is really, we also make sure to line it up when we return from holidays. Fun fact about our system, if you change you password on your own it restarts the clock from that day. permalink fedilink source parent
[–] pineapplelover@lemm.ee 2 points 3 years ago This is the proper way to do things (on your end, not the 8 character password at work). I also use email aliases from simplelogin in addition to strong and unique passwords. So any data breach from a site should be isolated. permalink fedilink source parent
[–] codapine@lemm.ee 1 point 3 years ago* (last edited 3 years ago) I use bitwarden on my android phone and home computer. Vivaldi browser on both devices with bw integration. I also was able to portable-load Vivaldi on my work pc, so one day when I'm not too busy, I intend to regen my work passwords (everything but the domain logon is web-based) with bitwarden so I never have to worry about how many ones and exclamation points I appended to my passwords. Now if I could only get them to replace Microsoft 365 OTPs with a smart card or RSA hardware token that'd be perfect. Especially when Teams and every other Microsoft app separately and individually decides for the nth time this week that they all need my credentials again because somebody sneezed near the work VPN server and caused the ntp to be off by a millisecond and invalidate my security certificate or... whatever the reason that happens. permalink fedilink source parent
[–] abraxas@lemmy.ml 0 points 3 years ago I do. This still happens to me regularly. Companies love to fuck with their password algorithms way too much. permalink fedilink source parent
[–] Sharkwellington@lemmy.one 4 points 3 years ago Brb stealing your cookies. permalink fedilink source parent