This practice is not recommended anymore, yet still found in many enterprises.

I am once again asking you to change your password
you are viewing a single comment's thread
view the rest of the comments
[–] 1 point 2 years ago (3 children)

Have you considered scripting it? For a while I worked at a place that required changing passwords every 60 days and it couldn't have been one of your previous 24 passwords. When checking out the policy I noticed there was no minimum password age so a quick for loop later and Bob becomes your mother's brother. Quickly cycling through 24 random passwords and back to my secure one and no more just adding the month/year.

Of course I reported it to cyber and about a year later they added a minimum age, now I'm hoping to get them to address an issue in AD that sidesteps changing passwords (though that one may be around for a while).

  • source
  • parent
  • hideshow 3 child comments
  • [–] 2 points 2 years ago (2 children)

    Unfortunately I don't think that's possible for my situation. Most of my passwords require logging into a portal and accepting terms of agreements.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago (1 child)

    Yeah, future me wonders why I even suggested it, I'm sure it probably violates the spirit of password change requirements.

  • source
  • parent
  • hideshow 1 child comment