Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
| From | Huge <Huge@nowhere.much.invalid> |
|---|---|
| Newsgroups | comp.misc |
| Subject | Re: [Link Posting] Password expiration is dead, long live your passwords |
| Date | 2019-06-11 21:08 +0000 |
| Organization | Piglet's Pickles & Preserves |
| Message-ID | <gmajjaFjvndU1@mid.individual.net> (permalink) |
| References | <MlpB1YKRhgDPsuv1m3oW7DKj@dont-email.me> <gm90qvF97g1U1@mid.individual.net> <gm9b6cFbbonU2@mid.individual.net> <slrnqfvqrh.2am.jj@iridium.wf32df> |
On 2019-06-11, Jim Jackson <jj@franjam.org.uk> wrote:
>>>>> Many enterprise-scale organizations (including TechCrunch's owner
>>>>> Verizon) require their users to change their passwords regularly. This
>>>>> is a spectacularly counterproductive policy.
>>>
>>> Why did this take so long? Why did so many people think it was a good
>>> idea to force password changes?
>>
>> Having spent many, many fruitless hours in shouty meetings with management,
>> trying to convince them that password changes are a stupid idea, the only
>> conclusion I can come to is that it's a religious matter.
>>
>
> Ditto and, being retired, my experience is 15 years old!
Yeah, I'm retired too, although "only" for 4 years. I don't miss the
shouty meetings in the least.
> The University's
> contract with their auditors, was for some consulting to be done into
> university procedures each year. One year was computer security. A bunch
> of PFY's(*), aka consultants, with clip boards and checkboxes to tick were
> sent around to "interview" verious computer support groups. I think we
> serious scared ours, when, after the tick sheet had been finished, we
> started questioning why they hadn't asked about x, y ... z and tried to
> question their whole approach. Of course the PFY hadn't a clue. I don't
> think the University computing management were happy when we submitted a
> complaint that the consultants had done a shoddy job.
Yep. "Tick box" computer security. I *loathed* it. (I ran an IT Security
function for quite a large bank.) People spent huge amounts of effort
trying to do security with 3 ring binders and cheap employees, whereas
I wanted to do it with paranoid geeks allowed to follow their noses. My
way actually worked (IOW, improved security), but didn't generate any
Excel spreadsheets with traffic light boxes, so management didn't like
it.
> And yes they tried to insist that everyone, even students, should change
> their passwords every month! We did get this altered so only passwords on
> admin and fincancial systems were covered. But the number of passwords on
> post-it-notes under keyboards, etc, mushroomed.
Yep. Depressing, isn't it? Still, I no longer have to GAS.
> (*) Pimply Faced Youth
*grin* I am entirely familiar with the Bastard Operator from Hell.
--
Today is Boomtime, the 16th day of Confusion in the YOLD 3185
Rising above bedlam
Back to comp.misc | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-02 21:55 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-03 20:28 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-03 20:35 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords RS Wood <rsw@therandymon.com> - 2019-06-09 09:10 -0400
Re: [Link Posting] Password expiration is dead, long live your passwords Richard Kettlewell <invalid@invalid.invalid> - 2019-06-09 14:22 +0100
Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-09 14:39 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-09 20:33 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords ant@zimage.comANT (Ant) - 2019-06-10 11:22 -0500
Re: [Link Posting] Password expiration is dead, long live your passwords Kerry Imming <kcimming@pobox.com> - 2019-06-10 11:42 -0500
Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-10 18:05 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Richard Kettlewell <invalid@invalid.invalid> - 2019-06-10 22:28 +0100
Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-11 16:42 +1000
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 09:39 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-11 20:29 +1000
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 11:01 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Mike Spencer <mds@bogus.nodomain.nowhere> - 2019-06-11 17:18 -0300
Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-12 00:04 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Mike Spencer <mds@bogus.nodomain.nowhere> - 2019-06-12 01:49 -0300
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:49 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:57 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Jim Jackson <jj@franjam.org.uk> - 2019-06-11 17:57 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-11 18:05 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 21:08 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-12 00:10 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:50 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-11 11:03 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-11 21:55 +1000
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 15:30 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Mike Spencer <mds@bogus.nodomain.nowhere> - 2019-06-11 17:43 -0300
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:58 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords kludge@panix.com (Scott Dorsey) - 2019-06-11 21:14 -0400
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:52 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-15 11:45 +1000
Re: [Link Posting] Password expiration is dead, long live your passwords kludge@panix.com (Scott Dorsey) - 2019-06-15 15:46 -0400
Re: [Link Posting] Password expiration is dead, long live your passwords Kerry Imming <kcimming@pobox.com> - 2019-06-11 12:19 -0500
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 18:21 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords kludge@panix.com (Scott Dorsey) - 2019-06-11 21:12 -0400
csiph-web