Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.misc > #18101 > unrolled thread

[Link Posting] Password expiration is dead, long live your passwords

Started byRich <rich@example.invalid>
First post2019-06-02 21:55 +0000
Last post2019-06-11 21:12 -0400
Articles 17 on this page of 37 — 11 participants

Back to article view | Back to comp.misc


Contents

  [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-02 21:55 +0000
    Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-03 20:28 +0000
      Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-03 20:35 +0000
      Re: [Link Posting] Password expiration is dead, long live your passwords RS Wood <rsw@therandymon.com> - 2019-06-09 09:10 -0400
        Re: [Link Posting] Password expiration is dead, long live your passwords Richard Kettlewell <invalid@invalid.invalid> - 2019-06-09 14:22 +0100
          Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-09 14:39 +0000
        Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-09 20:33 +0000
          Re: [Link Posting] Password expiration is dead, long live your passwords ant@zimage.comANT (Ant) - 2019-06-10 11:22 -0500
          Re: [Link Posting] Password expiration is dead, long live your passwords Kerry Imming <kcimming@pobox.com> - 2019-06-10 11:42 -0500
            Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-10 18:05 +0000
            Re: [Link Posting] Password expiration is dead, long live your passwords Richard Kettlewell <invalid@invalid.invalid> - 2019-06-10 22:28 +0100
    Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-11 16:42 +1000
      Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 09:39 +0000
        Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-11 20:29 +1000
          Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 11:01 +0000
            Re: [Link Posting] Password expiration is dead, long live your  passwords Mike Spencer <mds@bogus.nodomain.nowhere> - 2019-06-11 17:18 -0300
              Re: [Link Posting] Password expiration is dead, long live your  passwords Jerry Peters <jerry@example.invalid> - 2019-06-12 00:04 +0000
                Re: [Link Posting] Password expiration is dead, long live your  passwords Mike Spencer <mds@bogus.nodomain.nowhere> - 2019-06-12 01:49 -0300
                Re: [Link Posting] Password expiration is dead, long live your  passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:49 +0000
              Re: [Link Posting] Password expiration is dead, long live your  passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:57 +0000
        Re: [Link Posting] Password expiration is dead, long live your passwords Jim Jackson <jj@franjam.org.uk> - 2019-06-11 17:57 +0000
          Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-11 18:05 +0000
          Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 21:08 +0000
        Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-12 00:10 +0000
          Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:50 +0000
      Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-11 11:03 +0000
        Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-11 21:55 +1000
          Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 15:30 +0000
            Re: [Link Posting] Password expiration is dead, long live your  passwords Mike Spencer <mds@bogus.nodomain.nowhere> - 2019-06-11 17:43 -0300
              Re: [Link Posting] Password expiration is dead, long live your  passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:58 +0000
            Re: [Link Posting] Password expiration is dead, long live your passwords kludge@panix.com (Scott Dorsey) - 2019-06-11 21:14 -0400
              Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:52 +0000
              Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-15 11:45 +1000
                Re: [Link Posting] Password expiration is dead, long live your passwords kludge@panix.com (Scott Dorsey) - 2019-06-15 15:46 -0400
      Re: [Link Posting] Password expiration is dead, long live your passwords Kerry Imming <kcimming@pobox.com> - 2019-06-11 12:19 -0500
        Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 18:21 +0000
      Re: [Link Posting] Password expiration is dead, long live your passwords kludge@panix.com (Scott Dorsey) - 2019-06-11 21:12 -0400

Page 2 of 2 — ← Prev page 1 [2]


#18186

FromJim Jackson <jj@franjam.org.uk>
Date2019-06-11 17:57 +0000
Message-ID<slrnqfvqrh.2am.jj@iridium.wf32df>
In reply to#18179
>>>>   Many enterprise-scale organizations (including TechCrunch's owner
>>>>   Verizon) require their users to change their passwords regularly. This
>>>>   is a spectacularly counterproductive policy.
>>
>> Why did this take so long? Why did so many people think it was a good 
>> idea to force password changes?
>
> Having spent many, many fruitless hours in shouty meetings with management,
> trying to convince them that password changes are a stupid idea, the only
> conclusion I can come to is that it's a religious matter.
>

Ditto and, being retired, my experience is 15 years old! The University's 
contract with their auditors, was for some consulting to be done into 
university procedures each year. One year was computer security. A bunch 
of PFY's(*), aka consultants, with clip boards and checkboxes to tick were 
sent around to "interview" verious computer support groups. I think we 
serious scared ours, when, after the tick sheet had been finished, we 
started questioning why they hadn't asked about x, y ... z and tried to 
question their whole approach. Of course the PFY hadn't a clue. I don't 
think the University computing management were happy when we submitted a 
complaint that the consultants had done a shoddy job. 

And yes they tried to insist that everyone, even students, should change 
their passwords every month! We did get this altered so only passwords on 
admin and fincancial systems were covered. But the number of passwords on 
post-it-notes under keyboards, etc, mushroomed.



(*) Pimply Faced Youth

[toc] | [prev] | [next] | [standalone]


#18187

FromRich <rich@example.invalid>
Date2019-06-11 18:05 +0000
Message-ID<qdoqgc$umr$1@dont-email.me>
In reply to#18186
Jim Jackson <jj@franjam.org.uk> wrote:
>>>>>   Many enterprise-scale organizations (including TechCrunch's owner
>>>>>   Verizon) require their users to change their passwords regularly. This
>>>>>   is a spectacularly counterproductive policy.
>>>
>>> Why did this take so long? Why did so many people think it was a good 
>>> idea to force password changes?
>>
>> Having spent many, many fruitless hours in shouty meetings with management,
>> trying to convince them that password changes are a stupid idea, the only
>> conclusion I can come to is that it's a religious matter.
>>
> 
> aka consultants

https://dilbert.com/strip/1998-08-24

[toc] | [prev] | [next] | [standalone]


#18191

FromHuge <Huge@nowhere.much.invalid>
Date2019-06-11 21:08 +0000
Message-ID<gmajjaFjvndU1@mid.individual.net>
In reply to#18186
On 2019-06-11, Jim Jackson <jj@franjam.org.uk> wrote:
>>>>>   Many enterprise-scale organizations (including TechCrunch's owner
>>>>>   Verizon) require their users to change their passwords regularly. This
>>>>>   is a spectacularly counterproductive policy.
>>>
>>> Why did this take so long? Why did so many people think it was a good 
>>> idea to force password changes?
>>
>> Having spent many, many fruitless hours in shouty meetings with management,
>> trying to convince them that password changes are a stupid idea, the only
>> conclusion I can come to is that it's a religious matter.
>>
>
> Ditto and, being retired, my experience is 15 years old!

Yeah, I'm retired too, although "only" for 4 years. I don't miss the
shouty meetings in the least.

> The University's 
> contract with their auditors, was for some consulting to be done into 
> university procedures each year. One year was computer security. A bunch 
> of PFY's(*), aka consultants, with clip boards and checkboxes to tick were 
> sent around to "interview" verious computer support groups. I think we 
> serious scared ours, when, after the tick sheet had been finished, we 
> started questioning why they hadn't asked about x, y ... z and tried to 
> question their whole approach. Of course the PFY hadn't a clue. I don't 
> think the University computing management were happy when we submitted a 
> complaint that the consultants had done a shoddy job. 

Yep. "Tick box" computer security. I *loathed* it. (I ran an IT Security
function for quite a large bank.) People spent huge amounts of effort
trying to do security with 3 ring binders and cheap employees, whereas
I wanted to do it with paranoid geeks allowed to follow their noses. My
way actually worked (IOW, improved security), but didn't generate any
Excel spreadsheets with traffic light boxes, so management didn't like
it.

> And yes they tried to insist that everyone, even students, should change 
> their passwords every month! We did get this altered so only passwords on 
> admin and fincancial systems were covered. But the number of passwords on 
> post-it-notes under keyboards, etc, mushroomed.

Yep. Depressing, isn't it? Still, I no longer have to GAS.

> (*) Pimply Faced Youth

*grin* I am entirely familiar with the Bastard Operator from Hell.


-- 
Today is Boomtime, the 16th day of Confusion in the YOLD 3185
                  Rising above bedlam

[toc] | [prev] | [next] | [standalone]


#18193

FromJerry Peters <jerry@example.invalid>
Date2019-06-12 00:10 +0000
Message-ID<qdpfti$gep$2@dont-email.me>
In reply to#18179
Huge <Huge@nowhere.much.invalid> wrote:
> On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:
>> On 3/06/2019 7:55 am, Rich wrote:
>>>        ####################################################################
>>>        # ATTENTION: This post is a reference to a website.  The poster of #
>>>        # this Usenet article is not the author of the referenced website. #
>>>        ####################################################################
>>> 
>>> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long-
>>> live-your-passwords/>
>>> 
>>> The text below is a quotation from the URL above:
>>>>
>>>>   May was a momentous month, which marked a victory for sanity and
>>>>   pragmatism over irrational paranoia. I'm obviously not talking about
>>>>   politics. I'm talking about Microsoft finally - finally! but credit to
>>>>   them for doing this nonetheless! - removing the password expiration
>>>>   policies from their Windows 10 security baseline.
>>>>
>>>>   Although NIST and others precede this and deserve that credit, I think
>>>>   it's worth taking a moment to recognize this moment in time as truly a
>>>>   fundamental change in the industry.
>>>>
>>>>   - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019
>>>>
>>>>   Many enterprise-scale organizations (including TechCrunch's owner
>>>>   Verizon) require their users to change their passwords regularly. This
>>>>   is a spectacularly counterproductive policy.
>>>>
>>>>   ...
>>
>> Why did this take so long? Why did so many people think it was a good 
>> idea to force password changes?
> 
> Having spent many, many fruitless hours in shouty meetings with management,
> trying to convince them that password changes are a stupid idea, the only
> conclusion I can come to is that it's a religious matter.
> 
I'm guessing auditors -- with a checklist, one item of which is:
requires periodic password changes.
The auditors probably got it from some seminar in the distant past and
passed it around as received wisdom from then on.

[toc] | [prev] | [next] | [standalone]


#18198

FromHuge <Huge@nowhere.much.invalid>
Date2019-06-12 08:50 +0000
Message-ID<gmbsmvFs9q8U2@mid.individual.net>
In reply to#18193
On 2019-06-12, Jerry Peters <jerry@example.invalid> wrote:
> Huge <Huge@nowhere.much.invalid> wrote:
>> On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:
>>> On 3/06/2019 7:55 am, Rich wrote:
>>>>        ####################################################################
>>>>        # ATTENTION: This post is a reference to a website.  The poster of #
>>>>        # this Usenet article is not the author of the referenced website. #
>>>>        ####################################################################
>>>> 
>>>> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long-
>>>> live-your-passwords/>
>>>> 
>>>> The text below is a quotation from the URL above:
>>>>>
>>>>>   May was a momentous month, which marked a victory for sanity and
>>>>>   pragmatism over irrational paranoia. I'm obviously not talking about
>>>>>   politics. I'm talking about Microsoft finally - finally! but credit to
>>>>>   them for doing this nonetheless! - removing the password expiration
>>>>>   policies from their Windows 10 security baseline.
>>>>>
>>>>>   Although NIST and others precede this and deserve that credit, I think
>>>>>   it's worth taking a moment to recognize this moment in time as truly a
>>>>>   fundamental change in the industry.
>>>>>
>>>>>   - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019
>>>>>
>>>>>   Many enterprise-scale organizations (including TechCrunch's owner
>>>>>   Verizon) require their users to change their passwords regularly. This
>>>>>   is a spectacularly counterproductive policy.
>>>>>
>>>>>   ...
>>>
>>> Why did this take so long? Why did so many people think it was a good 
>>> idea to force password changes?
>> 
>> Having spent many, many fruitless hours in shouty meetings with management,
>> trying to convince them that password changes are a stupid idea, the only
>> conclusion I can come to is that it's a religious matter.
>> 
> I'm guessing auditors -- with a checklist, one item of which is:
> requires periodic password changes.
> The auditors probably got it from some seminar in the distant past and
> passed it around as received wisdom from then on.

Almost certainly true.


-- 
Today is Pungenday, the 17th day of Confusion in the YOLD 3185
                  Rising above bedlam

[toc] | [prev] | [next] | [standalone]


#18182

FromRich <rich@example.invalid>
Date2019-06-11 11:03 +0000
Message-ID<qdo1qp$84h$1@dont-email.me>
In reply to#18178
Sylvia Else <sylvia@email.invalid> wrote:
> On 3/06/2019 7:55 am, Rich wrote:
>>        ####################################################################
>>        # ATTENTION: This post is a reference to a website.  The poster of #
>>        # this Usenet article is not the author of the referenced website. #
>>        ####################################################################
>> 
>> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long-
>> live-your-passwords/>
>> 
>> The text below is a quotation from the URL above:
>>>
>>>   May was a momentous month, which marked a victory for sanity and
>>>   pragmatism over irrational paranoia. I'm obviously not talking about
>>>   politics. I'm talking about Microsoft finally - finally! but credit to
>>>   them for doing this nonetheless! - removing the password expiration
>>>   policies from their Windows 10 security baseline.
>>>
>>>   Although NIST and others precede this and deserve that credit, I think
>>>   it's worth taking a moment to recognize this moment in time as truly a
>>>   fundamental change in the industry.
>>>
>>>   - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019
>>>
>>>   Many enterprise-scale organizations (including TechCrunch's owner
>>>   Verizon) require their users to change their passwords regularly. This
>>>   is a spectacularly counterproductive policy.
>>>
>>>   ...
> 
> Why did this take so long?

Security theater is *very* slow to change.

> Why did so many people think it was a good idea to force password 
> changes?

This is one likely explanation:

https://themindunleashed.com/2016/02/the-famous-social-experiment-5-monkeys-and-a-ladder.html

[toc] | [prev] | [next] | [standalone]


#18183

FromSylvia Else <sylvia@email.invalid>
Date2019-06-11 21:55 +1000
Message-ID<gm9j54Fd0poU1@mid.individual.net>
In reply to#18182
On 11/06/2019 9:03 pm, Rich wrote:
> Sylvia Else <sylvia@email.invalid> wrote:
>> On 3/06/2019 7:55 am, Rich wrote:
>>>         ####################################################################
>>>         # ATTENTION: This post is a reference to a website.  The poster of #
>>>         # this Usenet article is not the author of the referenced website. #
>>>         ####################################################################
>>>
>>> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long-
>>> live-your-passwords/>
>>>
>>> The text below is a quotation from the URL above:
>>>>
>>>>    May was a momentous month, which marked a victory for sanity and
>>>>    pragmatism over irrational paranoia. I'm obviously not talking about
>>>>    politics. I'm talking about Microsoft finally - finally! but credit to
>>>>    them for doing this nonetheless! - removing the password expiration
>>>>    policies from their Windows 10 security baseline.
>>>>
>>>>    Although NIST and others precede this and deserve that credit, I think
>>>>    it's worth taking a moment to recognize this moment in time as truly a
>>>>    fundamental change in the industry.
>>>>
>>>>    - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019
>>>>
>>>>    Many enterprise-scale organizations (including TechCrunch's owner
>>>>    Verizon) require their users to change their passwords regularly. This
>>>>    is a spectacularly counterproductive policy.
>>>>
>>>>    ...
>>
>> Why did this take so long?
> 
> Security theater is *very* slow to change.
> 
>> Why did so many people think it was a good idea to force password
>> changes?
> 
> This is one likely explanation:
> 
> https://themindunleashed.com/2016/02/the-famous-social-experiment-5-monkeys-and-a-ladder.html
> 

Perhaps that's also why I have to endure "music" at McDonalds. 
Presumably, the received wisdom is that it improves profits. I've 
repeatedly asked whether there's any evidence. If anyone knows, they're 
not saying.

Sylvia.

[toc] | [prev] | [next] | [standalone]


#18184

FromHuge <Huge@nowhere.much.invalid>
Date2019-06-11 15:30 +0000
Message-ID<gm9vonFfnf0U1@mid.individual.net>
In reply to#18183
On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:
> On 11/06/2019 9:03 pm, Rich wrote:
>> Sylvia Else <sylvia@email.invalid> wrote:

[snip]

>>> Why did this take so long?
>> 
>> Security theater is *very* slow to change.
>> 
>>> Why did so many people think it was a good idea to force password
>>> changes?
>> 
>> This is one likely explanation:
>> 
>> https://themindunleashed.com/2016/02/the-famous-social-experiment-5-monkeys-and-a-ladder.html

It used to drive me crazy when people said of poor security practices
that "they'd always done it like that". My response, depending on mood,
was either "Well, you've always done it wrong, then", or, "we always
used to put children up chimneys and die of typhoid and cholera from
drinking water contaminated with our own shit. Do you want to carry on
doing *that*, too??"

> Perhaps that's also why I have to endure "music" at McDonalds. 
> Presumably, the received wisdom is that it improves profits. I've 
> repeatedly asked whether there's any evidence. If anyone knows, they're 
> not saying.

*applause* Speaking as someone who regularly turns "music" off, or asks
for it to be turned off, and has been known to disconnect loudspeakers,
I couldn't agree more.


-- 
Today is Boomtime, the 16th day of Confusion in the YOLD 3185
                  Rising above bedlam

[toc] | [prev] | [next] | [standalone]


#18190 — Re: [Link Posting] Password expiration is dead, long live your passwords

FromMike Spencer <mds@bogus.nodomain.nowhere>
Date2019-06-11 17:43 -0300
SubjectRe: [Link Posting] Password expiration is dead, long live your passwords
Message-ID<87zhmnq2e1.fsf@bogus.nodomain.nowhere>
In reply to#18184
Huge <Huge@nowhere.much.invalid> writes:

> It used to drive me crazy when people said of poor security practices
> that "they'd always done it like that". My response, depending on mood,
> was either "Well, you've always done it wrong, then", or, "we always
> used to put children up chimneys and die of typhoid and cholera from
> drinking water contaminated with our own shit. Do you want to carry on
> doing *that*, too??"


Sometimes there's a good explanation for "how we always done it",
albeit not always a reason to continue doing it.

In the 70s, I visited the "block shop" in Lunenburg, NS, where they
made tackle blocks with methods and gear that was a century or more
old -- everything from moby 4-sheave blocks for fishing gear to spiffy
little teak & stainless items for yachts.  Down in the cellar was a
blacksmith shop where they forged the eyebolts, hooks and other metal
parts.

When I was there, the smith was making hooks.  He split the end of a
1" dia. rod, bent the two ears of the split around a mandrel to
overlap and form an eye and forge-welded them together.  (Then the
other end was forged into the hook.)  I asked him why he was splitting
and welding to form the eye when just hot-punching the hole would have
been easier and given more predictable results.  "Stronger this way,
stronger this way." was all he had to say.

It was weeks later that it dawned on me that he had learned how to
forge hook eyes from his predecessor at the block shop, who had
learned it from his, etc. back to when the place was built.  And that
reached back to the days before Bessemer, open hearth and cheap steel,
the days when wrought iron was the article of commerce from which
"iron" things were made.  And he was absolutely right: Wrought iron
has a macroscopic grain structure similar to wood.  Punching a
load-bearing eye near the end of a piece of wrought iron predisposes
to failure similar to boring a hole near the end of a pine board and
then using it as a tension member. Splitting, wrapping and welding
(which you obviously can't do with wood) makes the grain run *around*
the eye.  The increase in strength and reliability far exceeds the
risk of possible defects in the forge weld.

So he was right, or rather, he had been right up to a point somewhere
between 1890 and 1910.

-- 
Mike Spencer                  Nova Scotia, Canada

[toc] | [prev] | [next] | [standalone]


#18201 — Re: [Link Posting] Password expiration is dead, long live your passwords

FromHuge <Huge@nowhere.much.invalid>
Date2019-06-12 08:58 +0000
SubjectRe: [Link Posting] Password expiration is dead, long live your passwords
Message-ID<gmbt5gFs9q8U6@mid.individual.net>
In reply to#18190
On 2019-06-11, Mike Spencer <mds@bogus.nodomain.nowhere> wrote:
>
> Huge <Huge@nowhere.much.invalid> writes:
>
>> It used to drive me crazy when people said of poor security practices
>> that "they'd always done it like that". My response, depending on mood,
>> was either "Well, you've always done it wrong, then", or, "we always
>> used to put children up chimneys and die of typhoid and cholera from
>> drinking water contaminated with our own shit. Do you want to carry on
>> doing *that*, too??"
>
>
> Sometimes there's a good explanation for "how we always done it",
> albeit not always a reason to continue doing it.

Good point. And in a similar vein, the IT world is very fond of re-inventing
the wheel.

-- 
Today is Pungenday, the 17th day of Confusion in the YOLD 3185
                  Rising above bedlam

[toc] | [prev] | [next] | [standalone]


#18195

Fromkludge@panix.com (Scott Dorsey)
Date2019-06-11 21:14 -0400
Message-ID<qdpjl4$69q$1@panix2.panix.com>
In reply to#18184
Huge  <usenet@huge.org.uk> wrote:
>On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:
>
>> Perhaps that's also why I have to endure "music" at McDonalds. 
>> Presumably, the received wisdom is that it improves profits. I've 
>> repeatedly asked whether there's any evidence. If anyone knows, they're 
>> not saying.
>
>*applause* Speaking as someone who regularly turns "music" off, or asks
>for it to be turned off, and has been known to disconnect loudspeakers,
>I couldn't agree more.

It is there to drive you away.  Just like the way the chairs at McDonalds
are designed to be uncomfortable.  They want you to sit and eat but they
don't want you to keep hanging around after you have eaten.  The whole
environment is designed to get you out so someone else can come in and 
pay for food.  It improves profits.
--scott


-- 
"C'est un Nagra. C'est suisse, et tres, tres precis."

[toc] | [prev] | [next] | [standalone]


#18199

FromHuge <Huge@nowhere.much.invalid>
Date2019-06-12 08:52 +0000
Message-ID<gmbspkFs9q8U3@mid.individual.net>
In reply to#18195
On 2019-06-12, Scott Dorsey <kludge@panix.com> wrote:
> Huge  <usenet@huge.org.uk> wrote:
>>On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:
>>
>>> Perhaps that's also why I have to endure "music" at McDonalds. 
>>> Presumably, the received wisdom is that it improves profits. I've 
>>> repeatedly asked whether there's any evidence. If anyone knows, they're 
>>> not saying.
>>
>>*applause* Speaking as someone who regularly turns "music" off, or asks
>>for it to be turned off, and has been known to disconnect loudspeakers,
>>I couldn't agree more.
>
> It is there to drive you away.  Just like the way the chairs at McDonalds
> are designed to be uncomfortable.  They want you to sit and eat

Good luck with that. I sit and eat in a Mikkey D's about once a decade.

> but they
> don't want you to keep hanging around after you have eaten.  The whole
> environment is designed to get you out so someone else can come in and 
> pay for food.  It improves profits.

But a good point, nonetheless.


-- 
Today is Pungenday, the 17th day of Confusion in the YOLD 3185
                  Rising above bedlam

[toc] | [prev] | [next] | [standalone]


#18209

FromSylvia Else <sylvia@email.invalid>
Date2019-06-15 11:45 +1000
Message-ID<gmj0tsFeoa9U1@mid.individual.net>
In reply to#18195
On 12/06/2019 11:14 am, Scott Dorsey wrote:
> Huge  <usenet@huge.org.uk> wrote:
>> On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:
>>
>>> Perhaps that's also why I have to endure "music" at McDonalds.
>>> Presumably, the received wisdom is that it improves profits. I've
>>> repeatedly asked whether there's any evidence. If anyone knows, they're
>>> not saying.
>>
>> *applause* Speaking as someone who regularly turns "music" off, or asks
>> for it to be turned off, and has been known to disconnect loudspeakers,
>> I couldn't agree more.
> 
> It is there to drive you away.  Just like the way the chairs at McDonalds
> are designed to be uncomfortable.  They want you to sit and eat but they
> don't want you to keep hanging around after you have eaten.  The whole
> environment is designed to get you out so someone else can come in and
> pay for food.  It improves profits.
> --scott
> 

This may indeed be the thinking, but does it work? Was any experimenting 
done, or did someone just suppose that it would have that effect, and 
it's been in place ever since, annoying people for no useful purpose?

Sylvia.

[toc] | [prev] | [next] | [standalone]


#18213

Fromkludge@panix.com (Scott Dorsey)
Date2019-06-15 15:46 -0400
Message-ID<qe3hul$e2p$1@panix2.panix.com>
In reply to#18209
Sylvia Else  <sylvia@email.invalid> wrote:
>On 12/06/2019 11:14 am, Scott Dorsey wrote:
>> 
>> It is there to drive you away.  Just like the way the chairs at McDonalds
>> are designed to be uncomfortable.  They want you to sit and eat but they
>> don't want you to keep hanging around after you have eaten.  The whole
>> environment is designed to get you out so someone else can come in and
>> pay for food.  It improves profits.
>
>This may indeed be the thinking, but does it work? Was any experimenting 
>done, or did someone just suppose that it would have that effect, and 
>it's been in place ever since, annoying people for no useful purpose?

Yes, an extensive amount of testing is done.  McDonalds has a rather large
corporate organization devoted to researching this sort of stuff, and they
employ an awful lot of experimental psych people.

As an engineering undergraduate, I took an industrial and organizational
psychology class with an adjunct professor who turned out to be one of
the marketing guys at Coca-Cola.  It was very interesting.
--scott

-- 
"C'est un Nagra. C'est suisse, et tres, tres precis."

[toc] | [prev] | [next] | [standalone]


#18185

FromKerry Imming <kcimming@pobox.com>
Date2019-06-11 12:19 -0500
Message-ID<qdonqh$f3g$1@dont-email.me>
In reply to#18178
On 6/11/2019 1:42 AM, Sylvia Else wrote:
> Why did this take so long? Why did so many people think it was a good 
> idea to force password changes?

My thought was that it dated back to logging in to a command line (as 
described in Clifford Stoll's book, "The Cuckoo's Egg") vs. a web page. 
A hacker then had access to explore the system as long as no changes 
were made that would cause them to be detected.  Changing the password 
would limit this exploration time.

- Kerry

[toc] | [prev] | [next] | [standalone]


#18188

FromHuge <Huge@nowhere.much.invalid>
Date2019-06-11 18:21 +0000
Message-ID<gma9ojFht61U2@mid.individual.net>
In reply to#18185
On 2019-06-11, Kerry Imming <kcimming@pobox.com> wrote:
> On 6/11/2019 1:42 AM, Sylvia Else wrote:
>> Why did this take so long? Why did so many people think it was a good 
>> idea to force password changes?
>
> My thought was that it dated back to logging in to a command line (as 
> described in Clifford Stoll's book, "The Cuckoo's Egg") vs. a web page. 
> A hacker then had access to explore the system as long as no changes 
> were made that would cause them to be detected.  Changing the password 
> would limit this exploration time.

On a Unix system, once you're logged on, changing the logon password makes
no difference whatsoever (unless the user tries to use a tool which re-reads
the password, e.g. sudo).

Not sure your web analogy is very good, either.


-- 
Today is Boomtime, the 16th day of Confusion in the YOLD 3185
                  Rising above bedlam

[toc] | [prev] | [next] | [standalone]


#18194

Fromkludge@panix.com (Scott Dorsey)
Date2019-06-11 21:12 -0400
Message-ID<qdpjh2$olm$1@panix2.panix.com>
In reply to#18178
Sylvia Else  <sylvia@email.invalid> wrote:
>
>Why did this take so long? Why did so many people think it was a good 
>idea to force password changes?

I can answer that question: because NIST told them it was a good idea.

Now.... whatever made the NIST standards people ever think it was a 
good idea, that I cannot answer.
--scott
-- 
"C'est un Nagra. C'est suisse, et tres, tres precis."

[toc] | [prev] | [standalone]


Page 2 of 2 — ← Prev page 1 [2]

Back to top | Article view | comp.misc


csiph-web