- My Forums
- Tiger Rant
- LSU Recruiting
- SEC Rant
- Saints Talk
- Pelicans Talk
- More Sports Board
- Fantasy Sports
- Golf Board
- Soccer Board
- O-T Lounge
- Tech Board
- Home/Garden Board
- Outdoor Board
- Health/Fitness Board
- Movie/TV Board
- Book Board
- Music Board
- Political Talk
- Money Talk
- Fark Board
- Gaming Board
- Travel Board
- Food/Drink Board
- Ticket Exchange
- TD Help Board
Customize My Forums- View All Forums
- Show Left Links
- Topic Sort Options
- Trending Topics
- Recent Topics
- Active Topics
Started By
Message
re: “Password does not meet minimum requirements”
Posted on 4/18/19 at 2:46 pm to Cowboyfan89
Posted on 4/18/19 at 2:46 pm to Cowboyfan89
quote:
have to keep a written log of all of my passwords with shorthand for what websites or applications they are used for.
I keep an Excel spreadsheet with most of mine. Have to actually scroll to see them all.
Posted on 4/18/19 at 2:46 pm to jcole4lsu
quote:
this is an absolutely terrible practice.
Made more likely by high standards, and requiring users to change passwords frequently.
This post was edited on 4/18/19 at 2:47 pm
Posted on 4/18/19 at 2:46 pm to TH03
quote:
That's all of our work passwords. People don't understand that making everyone change their password every 90 days leads to simpler passwords that are easier to figure out.
How any IT department in 2019 doesn't understand this is beyond me.
Because there are still too many regulatory requirements that dictate this, and when your security department is run by box-checking auditors, that's the result.
NIST has only just recently dropped frequent password changes and instead advocates long pass phrases and using MFA.
That's going to take time to trickle down through the box checking compliance groups that control security in large corporate environments.
Posted on 4/18/19 at 2:47 pm to Centinel
quote:
Length is far more important than complexity
TWSS
Posted on 4/18/19 at 2:48 pm to Centinel
It’ll take 15 years to change for NERC CIP
Posted on 4/18/19 at 2:48 pm to WaydownSouth
Mine is almost always some variation of FkUMtherFker1!
Posted on 4/18/19 at 2:48 pm to TigersSEC2010
quote:
You can thank the fricking idiots who made their passwords "password".
password1
:Brilliant:
Posted on 4/18/19 at 2:48 pm to ell_13
quote:
It’ll take 15 years to change for NERC CIP
I think you're being waaaay too optimistic for those jokers
Posted on 4/18/19 at 2:48 pm to windshieldman
quote:
Or after a few months it makes you change passwords but you can’t use your last 5 passwords ?
Those are rookie numbers. My work system wont let you use your last 25 passwords. Literally.
Posted on 4/18/19 at 2:48 pm to Cowboyfan89
quote:
I have to keep a written log of all of my passwords with shorthand for what websites or applications they are used for.
All of my passwords are on post-it notes taped to the inside of a cabinet door in my office. If we actually had an internal IT guy, I'm sure he would hate me
Posted on 4/18/19 at 2:51 pm to WhuckFistle
quote:Little known fact, this is actually the real reason Gaucho became a welder.
At my work, they now require the password to be at least 15 characters long.
Posted on 4/18/19 at 2:51 pm to jchamil
quote:
All of my passwords are on post-it notes taped to the inside of a cabinet door in my office. If we actually had an internal IT guy, I'm sure he would hate me
you frickers are the ones opening the spoofed emails too
Posted on 4/18/19 at 2:52 pm to Centinel
quote:
Because there are still too many regulatory requirements that dictate this, and when your security department is run by box-checking auditors, that's the result.
NIST has only just recently dropped frequent password changes and instead advocates long pass phrases and using MFA.
That's going to take time to trickle down through the box checking compliance groups that control security in large corporate environments.
This. Having worked a good chunk of IT in the banking industry, it's required. Why? Because of dipshits that do shite like this:
I don't want to lose my job because the company lost its arse in a data breach because of some careless a-hole. People don't realize that information security starts with you, not the IT department.
To be honest, I would like to see biometrics become more prevalent. While it too has it's flaws, it's far better than someone leaving their passwords out in plain sight.
Posted on 4/18/19 at 2:54 pm to fallguy_1978
quote:
you frickers are the ones opening the spoofed emails too
how else am i going to get my money from that Nigerian prince?
Posted on 4/18/19 at 2:54 pm to WaydownSouth
What I found interesting is that if you type :password: and then put your TD password in colons like you're doing an emoji, it censors it for you when you post, like so:
:password:********:
:password:********:
Posted on 4/18/19 at 2:55 pm to fallguy_1978
quote:
you frickers are the ones opening the spoofed emails too
To be fair, that shite is getting very hard to detect.
We've had multiple cases where our clients were compromised through Office365 phish, bad guy controlled the emails, searched the emails, found our client was due to receive an electronic deposit from one of our attorneys for a real estate transaction, contacted the attorney via email impersonating the client (with perfect English and grammar that matched the client's way of typing/writing) directing the direct deposit to a new account number. Our attorney questioned the change, and the bad guy responded...again with a very, very believable email. Thankfully our attorney was smart and made a phone call to confirm.
Office365 phishing is rampant right now because very few people use MFA and implicitly trust a Microsoft login page, even when spoofed.
Posted on 4/18/19 at 2:56 pm to windshieldman
I hate that one, reset your password every 3 months but you can't use any of your previous passwords
Posted on 4/18/19 at 2:56 pm to MorbidTheClown
PassWord#123456 Upper Case, Lower Case, length 15 characters with a special character.

Posted on 4/18/19 at 2:59 pm to TH03
quote:
It's annoying af
Tell me about it. We actually tried to get out ahead of this and follow NIST guidelines and change our password policy because A) it's the correct thing to do and B) makes it easier on our employees at the same time. Win-win right?
Our biggest clients said "nope, you can't do that. You have to maintain the frequent password change and complexity requirements."
We shot back with "we're following NIST guidelines."
They shot back with "we don't care." Again, this wasn't the actual security analysts and engineers who actually know and give a shite about this stuff. It was a group of auditors in India. They have their checklists, and they will not deviate from them. Even when it makes zero sense when it comes to improving information and data security.
Popular
Back to top


0









