top 50 comments

sorted by: hot top controversial new old
[–] 101 points 3 years ago (34 children)

And despite security recommendations, too many IT depts still force password resets every 90 days...

And people confronted with this change their password from "p@55w0rd!1" to "p@55w0rd@2". Yep extra-secure!

  • source
  • hideshow 34 child comments
  • [–] 10 points 3 years ago (15 children)

    Some IT guys have caught on to this and require 2 digits difference.

    So "ThisJobSucks#11" becomes "ThisJobSucks#22"

  • source
  • parent
  • hideshow 15 child comments
  • [–] 13 points 3 years ago (14 children)

    How would they know how many digits changed? They don't store the password in cleartext.

    Right?

    ...

  • source
  • parent
  • hideshow 14 child comments
  • load more comments (12 replies)
  • [–] 8 points 3 years ago (2 children)

    {Sitename}+{SaLt}+{yymmdd of password change} easy peasy

  • source
  • parent
  • hideshow 2 child comments
  • [–] 9 points 3 years ago

    I college we had to change our password every semester. Guess who added the semester number onto the end of their password. Hint: everyone.

    Same as a government job that required monthly password changes. Well, at least those people had more security than the post-it note on the monitor people

  • source
  • parent
  • load more comments (1 reply)
  • [–] 5 points 3 years ago (1 child)

    And despite security recommendations, too many IT depts still force password resets every 90 days...

    It could be for contractual or for insurance reasons. We have some contracts with government agencies that require it, and our cyberinsurance also does. Even though NIST has been recommending for years to do long passphrase + MFA and no reset unless you suspect compromise.

    So yeah, the reason behind this might not be just plain incompetence.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • [–] 5 points 3 years ago

    The worst is when you have a bunch of independent systems that all have their own login info, all configured by the dame IT department, all with different forced reset timers.

  • source
  • parent
  • [–] 4 points 3 years ago

    I've had arguments with clients' IT security about this in the past where they demanded forced password resets. Citing NIST controls that insist you should avoid them was apparently insufficient.

  • source
  • parent
  • [–] 47 points 3 years ago (32 children)

    Who still isn't using a password manager?

  • source
  • hideshow 32 child comments
  • [–] 57 points 3 years ago (4 children)

    The most infuriating part is when this happens while using a password from a password manager

  • source
  • parent
  • hideshow 4 child comments
  • [–] [S] 16 points 3 years ago (3 children)

    The fact this happens is infuriating. 😣

  • source
  • parent
  • hideshow 3 child comments
  • [–] 21 points 3 years ago (7 children)

    What if I were to tell you my password manager password is the most vulnerable of all?

    Nobody would guess it's hunter2.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 7 points 3 years ago (6 children)

    I promise you that does not help.

    I suspect a large number of these incidents are due to the password field in the login page allowing fewer characters than the field in the sign up page, so the password gets truncated. A couple of help desk meat shields have confirmed that for me, but mostly I think this because it seems to fix itself if I use a shorter password.

    How short, you ask? Who tf knows! They sure as shit won't tell you! Just spend the next 20 minutes trying shit til it works, because you have nothing better to do with your time!

  • source
  • parent
  • hideshow 6 child comments
  • load more comments (2 replies)
  • load more comments (8 replies)
    [–] 33 points 3 years ago (1 child)
  • [+] 16 points 3 years ago* (last edited 2 years ago) (10 children)
  • [–] 22 points 3 years ago (8 children)

    Or use a fucking password manager like Bitwarden or Keepass

  • source
  • parent
  • hideshow 8 child comments
  • [–] 9 points 3 years ago (5 children)

    I won't say where I work but we have strict password requirements including that they have to be exactly 8 characters long.

    Yeah our passwords aren't very secure as we also have to change them every 90 days and if you miss the window by 3 days you have to call the IT desk to reset it which takes about 45 minutes to an hour. And in that time you basically can't get anything done.

    At home I use a password manager and all my passwords are randomly generated and whenever possible 2fa is enabled.

  • source
  • parent
  • hideshow 5 child comments
  • [–] 7 points 3 years ago

    Not sure if you're in the US. But if you are, you should leave this anonymously on the security team's desks.

    > Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator. - NIST control SP 800-63B Section 5.1.1.2

    Basically a fairly widespread standard of security. All kinda of complaince you can fall out of if you do business with anyone who cares about NIST controls.

  • source
  • parent
  • load more comments (3 replies)
  • load more comments (2 replies)
  • load more comments (1 reply)
    [–] 11 points 3 years ago (1 child)

    And that’s why I generate my passwords randomly.

    Thank you Bitwarden.

  • source
  • hideshow 1 child comment
  • [–] 10 points 3 years ago (1 child)

    Ahh, so you all also shop at target online, eh?

  • source
  • hideshow 1 child comment
  • [+] 6 points 3 years ago* (last edited 2 years ago) (1 child)
    load more comments (1 reply)
    [–] 4 points 3 years ago

    Why is that? Couldn't find anything on Google.

  • source
  • load more comments
    view more: next ›