Started By
Message

re: Required password changes

Posted on 5/21/20 at 4:00 pm to
Posted by Centinel
Idaho
Member since Sep 2016
43390 posts
Posted on 5/21/20 at 4:00 pm to
quote:

If you are not in the hospital on one of the computers there, you have to authenticate your logging in via a cell phone app.




Good to hear. MFA should be applied to any and all external access to internal systems, period. Hell we even MFA our internal critical servers. As in if I'm in the office on our secure network, I still have to MFA to access our critical systems.
Posted by TH03
Mogadishu
Member since Dec 2008
171071 posts
Posted on 5/21/20 at 4:00 pm to
We finally went to 2FA for email, but not for anything else. It’s a start, but the portal with access to my pay statements, benefit elections, W2, etc is more important to secure than my email so it’s annoying.
Posted by Wally Sparks
Atlanta
Member since Feb 2013
29263 posts
Posted on 5/21/20 at 4:00 pm to
Ours is every 30 days.

fricking sucks.
Posted by ksayetiger
Centenary Gents
Member since Jul 2007
68368 posts
Posted on 5/21/20 at 4:03 pm to
quote:

just change it to the girls name im texting at the time. being its always a different one




one day one of those girls might actually text you back. good luck!
Posted by GRTiger
On a roof eating alligator pie
Member since Dec 2008
63214 posts
Posted on 5/21/20 at 4:03 pm to
quote:

Did you not read it?


Before you even posted it, actually.

It's a very useful study to stress the importance of avoiding incremental password changes.

I will say that expiration is the least important of the various password requirements. Length is the by far the most important from a security standpoint. If I am looking at password configs from a security standpoint, I'd be more inclined to raise the flag on settings that required a 6 character, digits only password, to be changed every 7 days, than I would be a 12 character, complex password, to be changed once a year.

But as stated before, adding one extra requirement, all other things equal, won't make it "easier" to crack, regardless of the incremental increase in strength.
Posted by TH03
Mogadishu
Member since Dec 2008
171071 posts
Posted on 5/21/20 at 4:08 pm to
quote:

than I would be a 12 character, complex password, to be changed once a year.



I’d be okay with this.

Our standards are a joke and they reset every 90 days. That’s a bad combo.
Posted by TigerChief10
Member since Dec 2012
10858 posts
Posted on 5/21/20 at 4:08 pm to
Nothing is worse than them making you change it on a Friday and not remembering it after the weekend.
Posted by Boring
Member since Feb 2019
3792 posts
Posted on 5/21/20 at 4:08 pm to
My girlfriend's mom uses some password trick she picked up from some guy on NPR to help her remember. Her passwords are usually like this:

yalacb4881
yalanf4881
yalafb4881

You
Are
Looking
At
(Chase Bank or NetFlix or FaceBook)

And the number stays the same, it's her son's birthday backwards (January 8th, 1984). Maybe not the most secure, but not bad for an older lady IMO
Posted by nuwaydawg
Member since Nov 2007
1929 posts
Posted on 5/21/20 at 4:11 pm to
My problem with tigerdroppings

I can access food/drink, travel, OT, Politics etc.

I can't access the UGA and recruiting board without a password.

Is there such a thing as partial accessibility?

Tried to have a new password sent to my e-mail...nothing.
Posted by TigerstuckinMS
Member since Nov 2005
33687 posts
Posted on 5/21/20 at 4:12 pm to
quote:

but not bad for an older lady IMO

pics?
Posted by TigerstuckinMS
Member since Nov 2005
33687 posts
Posted on 5/21/20 at 4:12 pm to
quote:

I can't access the UGA and recruiting board without a password.

It's harder to accidentally access the UGA board?

That's a feature.
This post was edited on 5/21/20 at 4:13 pm
Posted by Slingscode
Houston, TX
Member since Sep 2011
1867 posts
Posted on 5/21/20 at 4:35 pm to
You sir are a prick, and really know nothing about which you speak.

1Password is your friend.

Thank me later.
Posted by Golfer
Member since Nov 2005
75052 posts
Posted on 5/21/20 at 4:37 pm to
quote:

That IT "cuck" is protecting you from allowing a virus to take down your entire network.


There's been research that says forcing password changes too often is actually less-protective given that users will simplify their passwords and/or store them in an unsecured location.
Posted by shaqazoolu
Baton Rouge
Member since Jun 2008
600 posts
Posted on 5/21/20 at 5:20 pm to
The reason this is a requirement is that teams like mine get into client networks all the time because 50 morons out of a 500 person company are using "Summer2020!" as their password and just rotate through seasons. It realistically could be a choice between whining about having to use a password that doesn't suck versus having to find another job.
first pageprev pagePage 3 of 3Next pagelast page
refresh

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on Twitter, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookTwitterInstagram