Started By
Message

re: “Password does not meet minimum requirements”

Posted on 4/18/19 at 2:46 pm to
Posted by Steadyhands
Slightly above I-10
Member since May 2016
7201 posts
Posted on 4/18/19 at 2:46 pm to
quote:

have to keep a written log of all of my passwords with shorthand for what websites or applications they are used for.


I keep an Excel spreadsheet with most of mine. Have to actually scroll to see them all.
Posted by Lima Whiskey
Member since Apr 2013
22594 posts
Posted on 4/18/19 at 2:46 pm to
quote:

this is an absolutely terrible practice.


Made more likely by high standards, and requiring users to change passwords frequently.
This post was edited on 4/18/19 at 2:47 pm
Posted by Centinel
Idaho
Member since Sep 2016
46666 posts
Posted on 4/18/19 at 2:46 pm to
quote:

That's all of our work passwords. People don't understand that making everyone change their password every 90 days leads to simpler passwords that are easier to figure out.

How any IT department in 2019 doesn't understand this is beyond me.



Because there are still too many regulatory requirements that dictate this, and when your security department is run by box-checking auditors, that's the result.

NIST has only just recently dropped frequent password changes and instead advocates long pass phrases and using MFA.

That's going to take time to trickle down through the box checking compliance groups that control security in large corporate environments.
Posted by MorbidTheClown
Baton Rouge
Member since Jan 2015
76771 posts
Posted on 4/18/19 at 2:47 pm to
quote:

Length is far more important than complexity


TWSS
Posted by ell_13
Member since Apr 2013
88411 posts
Posted on 4/18/19 at 2:48 pm to
It’ll take 15 years to change for NERC CIP
Posted by ConfusedHawgInMO
Member since Apr 2014
3578 posts
Posted on 4/18/19 at 2:48 pm to
Mine is almost always some variation of FkUMtherFker1!
Posted by Chad504boy
4 posts
Member since Feb 2005
179857 posts
Posted on 4/18/19 at 2:48 pm to
quote:

You can thank the fricking idiots who made their passwords "password".


password1

:Brilliant:
Posted by Centinel
Idaho
Member since Sep 2016
46666 posts
Posted on 4/18/19 at 2:48 pm to
quote:

It’ll take 15 years to change for NERC CIP



I think you're being waaaay too optimistic for those jokers

Posted by joshwj93
Member since Feb 2019
627 posts
Posted on 4/18/19 at 2:48 pm to
quote:

Or after a few months it makes you change passwords but you can’t use your last 5 passwords ?




Those are rookie numbers. My work system wont let you use your last 25 passwords. Literally.
Posted by jchamil
Member since Nov 2009
19880 posts
Posted on 4/18/19 at 2:48 pm to
quote:

I have to keep a written log of all of my passwords with shorthand for what websites or applications they are used for.


All of my passwords are on post-it notes taped to the inside of a cabinet door in my office. If we actually had an internal IT guy, I'm sure he would hate me
Posted by saint tiger225
San Diego
Member since Jan 2011
49201 posts
Posted on 4/18/19 at 2:51 pm to
quote:

At my work, they now require the password to be at least 15 characters long. 
Little known fact, this is actually the real reason Gaucho became a welder.
Posted by fallguy_1978
Best States #50
Member since Feb 2018
53813 posts
Posted on 4/18/19 at 2:51 pm to
quote:

All of my passwords are on post-it notes taped to the inside of a cabinet door in my office. If we actually had an internal IT guy, I'm sure he would hate me

you frickers are the ones opening the spoofed emails too
Posted by Pechon
unperson
Member since Oct 2011
7748 posts
Posted on 4/18/19 at 2:52 pm to
quote:

Because there are still too many regulatory requirements that dictate this, and when your security department is run by box-checking auditors, that's the result.

NIST has only just recently dropped frequent password changes and instead advocates long pass phrases and using MFA.

That's going to take time to trickle down through the box checking compliance groups that control security in large corporate environments.


This. Having worked a good chunk of IT in the banking industry, it's required. Why? Because of dipshits that do shite like this:



I don't want to lose my job because the company lost its arse in a data breach because of some careless a-hole. People don't realize that information security starts with you, not the IT department.

To be honest, I would like to see biometrics become more prevalent. While it too has it's flaws, it's far better than someone leaving their passwords out in plain sight.
Posted by MorbidTheClown
Baton Rouge
Member since Jan 2015
76771 posts
Posted on 4/18/19 at 2:54 pm to
quote:

you frickers are the ones opening the spoofed emails too


how else am i going to get my money from that Nigerian prince?
Posted by Box Geauxrilla
Member since Jun 2013
19221 posts
Posted on 4/18/19 at 2:54 pm to
What I found interesting is that if you type :password: and then put your TD password in colons like you're doing an emoji, it censors it for you when you post, like so:

:password:********:
Posted by TH03
Mogadishu
Member since Dec 2008
172004 posts
Posted on 4/18/19 at 2:55 pm to
It's annoying af
Posted by Centinel
Idaho
Member since Sep 2016
46666 posts
Posted on 4/18/19 at 2:55 pm to
quote:

you frickers are the ones opening the spoofed emails too


To be fair, that shite is getting very hard to detect.

We've had multiple cases where our clients were compromised through Office365 phish, bad guy controlled the emails, searched the emails, found our client was due to receive an electronic deposit from one of our attorneys for a real estate transaction, contacted the attorney via email impersonating the client (with perfect English and grammar that matched the client's way of typing/writing) directing the direct deposit to a new account number. Our attorney questioned the change, and the bad guy responded...again with a very, very believable email. Thankfully our attorney was smart and made a phone call to confirm.

Office365 phishing is rampant right now because very few people use MFA and implicitly trust a Microsoft login page, even when spoofed.
Posted by tduecen
Member since Nov 2006
161246 posts
Posted on 4/18/19 at 2:56 pm to
I hate that one, reset your password every 3 months but you can't use any of your previous passwords
Posted by CHSTigersFan
Charleston, Arkansas
Member since Jan 2005
2738 posts
Posted on 4/18/19 at 2:56 pm to
PassWord#123456 Upper Case, Lower Case, length 15 characters with a special character.
Posted by Centinel
Idaho
Member since Sep 2016
46666 posts
Posted on 4/18/19 at 2:59 pm to
quote:

It's annoying af


Tell me about it. We actually tried to get out ahead of this and follow NIST guidelines and change our password policy because A) it's the correct thing to do and B) makes it easier on our employees at the same time. Win-win right?

Our biggest clients said "nope, you can't do that. You have to maintain the frequent password change and complexity requirements."

We shot back with "we're following NIST guidelines."

They shot back with "we don't care." Again, this wasn't the actual security analysts and engineers who actually know and give a shite about this stuff. It was a group of auditors in India. They have their checklists, and they will not deviate from them. Even when it makes zero sense when it comes to improving information and data security.



first pageprev pagePage 2 of 4Next pagelast page

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on X, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookXInstagram