Started By
Message

re: Why do we have to reset passwords so regularly?

Posted on 7/30/20 at 9:01 am to
Posted by TheChosenOne
Member since Dec 2005
18901 posts
Posted on 7/30/20 at 9:01 am to
If you use long passphrases and multi-factor authentication, you shouldn't need to change your password unless a breach is suspected or discovered. The problem is many services/systems either can't support MFA or don't want to make it a requirement.

So, just use a password manager like LastPass.
Posted by Hulkklogan
Baton Rouge, LA
Member since Oct 2010
43482 posts
Posted on 7/30/20 at 9:07 am to
LastPass is a game changer


But honestly, it's been around a decade or longer that password security measures have changed and studies found that regularly changing passwords increases risk of hacks because people use less secure passwords, or re-use the same variation of passwords over and over.

The companies that still require a new password every 60-90 days are doing it wrong. You're far better off with strict password requirements and only requiring a change annually.
This post was edited on 7/30/20 at 9:08 am
Posted by Centinel
Idaho
Member since Sep 2016
46805 posts
Posted on 7/30/20 at 9:08 am to
Hence the NIST guidelines I mentioned earlier.

Posted by TU Rob
Birmingham
Member since Nov 2008
13586 posts
Posted on 7/30/20 at 9:08 am to
We're finally going away from our archaic 45 day password change schedule. I think it is 6 months now, but we're going to the passphrase model. It has to be so many words and so many characters when combined, so that will be easier to remember than the capital letter, lowercase letter, number/symbol requirement currently.
Posted by Hulkklogan
Baton Rouge, LA
Member since Oct 2010
43482 posts
Posted on 7/30/20 at 9:09 am to
quote:

Hence the NIST guidelines I mentioned earlier.



Yep


MFA should be a must at any company these days, really.
Posted by Centinel
Idaho
Member since Sep 2016
46805 posts
Posted on 7/30/20 at 9:11 am to
quote:

MFA should be a must at any company these days, really.



I don't know how many phishing emails I see a day from O365 accounts because people aren't using MFA.

My firm wanted to roll out O365 initially without MFA to "make sure it went smooth". I said frick that noise.
Posted by TH03
Mogadishu
Member since Dec 2008
172004 posts
Posted on 7/30/20 at 9:13 am to
MFA is so easy but people are so dumb. I get a text with a code, enter it, boom I’m logged in. Then I get an email on 2 different accounts telling me there was a login so that if it wasn’t me, I’ll know immediately.

It works great, but we still have the dumb 90 day password shite.

Edit: we’re on O365 now.
This post was edited on 7/30/20 at 9:14 am
Posted by Oilfieldbiology
Member since Nov 2016
42813 posts
Posted on 7/30/20 at 9:13 am to
I have a locked Notes note in my phone for all my computer password. Why? Because I have like 17 and they are all different.
Posted by Hulkklogan
Baton Rouge, LA
Member since Oct 2010
43482 posts
Posted on 7/30/20 at 9:14 am to
Ours is weird. It's a hybrid of bad and good... my guess is that is for that same reasoning. 90 day password changes, but pretty strict requirements on passwords and MFA is instated. It is actually a real pain in the arse, I have to change my password on my work computer, my home computer, my phone, and my tablet every 90 days to use O365 products, but they all have to re-auth through the MFA. I already started just using the Outlook web app because if I missed a device using Outlook I was getting locked out, and im considering just using all web app versions of O365 products just so I don't have to deal with that horseshite anymore. I'm not in the internal IT department so I have no control over that policy.
This post was edited on 7/30/20 at 9:16 am
Posted by Oilfieldbiology
Member since Nov 2016
42813 posts
Posted on 7/30/20 at 9:15 am to
quote:

Which is why NIST guidelines (and anyone in cybersecurity with common sense) advocate not requiring frequent password changes and instead push to using long passphrases.


Man this would be great
Posted by Oilfieldbiology
Member since Nov 2016
42813 posts
Posted on 7/30/20 at 9:17 am to
quote:

I already started just using the Outlook web app, and im considering just using all web app versions of O365 products just so I don't have to deal with that horseshite anymore.


This is what the companies want. Why? I don’t know but everything is moving to web based apps as opposed to downloadable programs
Posted by Centinel
Idaho
Member since Sep 2016
46805 posts
Posted on 7/30/20 at 9:18 am to
quote:

It works great, but we still have the dumb 90 day password shite.


As do we. We tried to change our policy to follow the NIST guidelines, but our largest clients said nope. We pointed out the NIST guidelines to them. They responded with "frequent password changes are still best practice".

Posted by Demshoes
Up in here
Member since Aug 2015
10758 posts
Posted on 7/30/20 at 9:18 am to
I stick with Password. Haven't had any issues.
Posted by Pettifogger
I don't really care, Margaret
Member since Feb 2012
87755 posts
Posted on 7/30/20 at 9:19 am to
I don't understand why Tigerdroppings can have robust security and no issues but my work requires me to change my PW every 90 days

I mean, I can't even type my password in the forum without the forum auto blocking it out for me: *********

meanwhile our work systems are archaic
Posted by tommy2tone1999
St. George, LA
Member since Sep 2008
7846 posts
Posted on 7/30/20 at 9:21 am to
quote:

Why do we have to reset passwords so regularly?


Section 404 of the Sarbanes-Oxley Act of 2002. Greater security requirements for publicly trades companies, and it just spilled over to everyone else.
Posted by eScott
Member since Oct 2008
11376 posts
Posted on 7/30/20 at 9:22 am to
(no message)
This post was edited on 7/30/20 at 9:39 am
Posted by Centinel
Idaho
Member since Sep 2016
46805 posts
Posted on 7/30/20 at 9:24 am to
quote:

Because websites get hacked and passwords get posted on LINK


So then people reuse the same passwords or use some simple iteration like putting a 1 on the end, and then use the same passwords for multiple sites, so then when they get posted on pastebin it's easy to compromise multiple accounts for the same person.

Posted by eScott
Member since Oct 2008
11376 posts
Posted on 7/30/20 at 9:35 am to
Edit because I don't want to get banned posting members passwords
This post was edited on 7/30/20 at 9:40 am
Posted by FLTech
he/won
Member since Sep 2017
29195 posts
Posted on 7/30/20 at 9:52 am to
Pooh what is this?? Googling it right now
Posted by Centinel
Idaho
Member since Sep 2016
46805 posts
Posted on 7/30/20 at 9:55 am to
quote:

Edit because I don't want to get banned posting members passwords


The first think I did was to look for Chicken....not there though.
first pageprev pagePage 2 of 3Next pagelast page

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on X, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookXInstagram