Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.misc > #18101 > unrolled thread
| Started by | Rich <rich@example.invalid> |
|---|---|
| First post | 2019-06-02 21:55 +0000 |
| Last post | 2019-06-11 21:12 -0400 |
| Articles | 17 on this page of 37 — 11 participants |
Back to article view | Back to comp.misc
[Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-02 21:55 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-03 20:28 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-03 20:35 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords RS Wood <rsw@therandymon.com> - 2019-06-09 09:10 -0400
Re: [Link Posting] Password expiration is dead, long live your passwords Richard Kettlewell <invalid@invalid.invalid> - 2019-06-09 14:22 +0100
Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-09 14:39 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-09 20:33 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords ant@zimage.comANT (Ant) - 2019-06-10 11:22 -0500
Re: [Link Posting] Password expiration is dead, long live your passwords Kerry Imming <kcimming@pobox.com> - 2019-06-10 11:42 -0500
Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-10 18:05 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Richard Kettlewell <invalid@invalid.invalid> - 2019-06-10 22:28 +0100
Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-11 16:42 +1000
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 09:39 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-11 20:29 +1000
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 11:01 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Mike Spencer <mds@bogus.nodomain.nowhere> - 2019-06-11 17:18 -0300
Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-12 00:04 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Mike Spencer <mds@bogus.nodomain.nowhere> - 2019-06-12 01:49 -0300
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:49 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:57 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Jim Jackson <jj@franjam.org.uk> - 2019-06-11 17:57 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-11 18:05 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 21:08 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-12 00:10 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:50 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-11 11:03 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-11 21:55 +1000
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 15:30 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Mike Spencer <mds@bogus.nodomain.nowhere> - 2019-06-11 17:43 -0300
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:58 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords kludge@panix.com (Scott Dorsey) - 2019-06-11 21:14 -0400
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:52 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-15 11:45 +1000
Re: [Link Posting] Password expiration is dead, long live your passwords kludge@panix.com (Scott Dorsey) - 2019-06-15 15:46 -0400
Re: [Link Posting] Password expiration is dead, long live your passwords Kerry Imming <kcimming@pobox.com> - 2019-06-11 12:19 -0500
Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 18:21 +0000
Re: [Link Posting] Password expiration is dead, long live your passwords kludge@panix.com (Scott Dorsey) - 2019-06-11 21:12 -0400
Page 2 of 2 — ← Prev page 1 [2]
| From | Jim Jackson <jj@franjam.org.uk> |
|---|---|
| Date | 2019-06-11 17:57 +0000 |
| Message-ID | <slrnqfvqrh.2am.jj@iridium.wf32df> |
| In reply to | #18179 |
>>>> Many enterprise-scale organizations (including TechCrunch's owner >>>> Verizon) require their users to change their passwords regularly. This >>>> is a spectacularly counterproductive policy. >> >> Why did this take so long? Why did so many people think it was a good >> idea to force password changes? > > Having spent many, many fruitless hours in shouty meetings with management, > trying to convince them that password changes are a stupid idea, the only > conclusion I can come to is that it's a religious matter. > Ditto and, being retired, my experience is 15 years old! The University's contract with their auditors, was for some consulting to be done into university procedures each year. One year was computer security. A bunch of PFY's(*), aka consultants, with clip boards and checkboxes to tick were sent around to "interview" verious computer support groups. I think we serious scared ours, when, after the tick sheet had been finished, we started questioning why they hadn't asked about x, y ... z and tried to question their whole approach. Of course the PFY hadn't a clue. I don't think the University computing management were happy when we submitted a complaint that the consultants had done a shoddy job. And yes they tried to insist that everyone, even students, should change their passwords every month! We did get this altered so only passwords on admin and fincancial systems were covered. But the number of passwords on post-it-notes under keyboards, etc, mushroomed. (*) Pimply Faced Youth
[toc] | [prev] | [next] | [standalone]
| From | Rich <rich@example.invalid> |
|---|---|
| Date | 2019-06-11 18:05 +0000 |
| Message-ID | <qdoqgc$umr$1@dont-email.me> |
| In reply to | #18186 |
Jim Jackson <jj@franjam.org.uk> wrote: >>>>> Many enterprise-scale organizations (including TechCrunch's owner >>>>> Verizon) require their users to change their passwords regularly. This >>>>> is a spectacularly counterproductive policy. >>> >>> Why did this take so long? Why did so many people think it was a good >>> idea to force password changes? >> >> Having spent many, many fruitless hours in shouty meetings with management, >> trying to convince them that password changes are a stupid idea, the only >> conclusion I can come to is that it's a religious matter. >> > > aka consultants https://dilbert.com/strip/1998-08-24
[toc] | [prev] | [next] | [standalone]
| From | Huge <Huge@nowhere.much.invalid> |
|---|---|
| Date | 2019-06-11 21:08 +0000 |
| Message-ID | <gmajjaFjvndU1@mid.individual.net> |
| In reply to | #18186 |
On 2019-06-11, Jim Jackson <jj@franjam.org.uk> wrote:
>>>>> Many enterprise-scale organizations (including TechCrunch's owner
>>>>> Verizon) require their users to change their passwords regularly. This
>>>>> is a spectacularly counterproductive policy.
>>>
>>> Why did this take so long? Why did so many people think it was a good
>>> idea to force password changes?
>>
>> Having spent many, many fruitless hours in shouty meetings with management,
>> trying to convince them that password changes are a stupid idea, the only
>> conclusion I can come to is that it's a religious matter.
>>
>
> Ditto and, being retired, my experience is 15 years old!
Yeah, I'm retired too, although "only" for 4 years. I don't miss the
shouty meetings in the least.
> The University's
> contract with their auditors, was for some consulting to be done into
> university procedures each year. One year was computer security. A bunch
> of PFY's(*), aka consultants, with clip boards and checkboxes to tick were
> sent around to "interview" verious computer support groups. I think we
> serious scared ours, when, after the tick sheet had been finished, we
> started questioning why they hadn't asked about x, y ... z and tried to
> question their whole approach. Of course the PFY hadn't a clue. I don't
> think the University computing management were happy when we submitted a
> complaint that the consultants had done a shoddy job.
Yep. "Tick box" computer security. I *loathed* it. (I ran an IT Security
function for quite a large bank.) People spent huge amounts of effort
trying to do security with 3 ring binders and cheap employees, whereas
I wanted to do it with paranoid geeks allowed to follow their noses. My
way actually worked (IOW, improved security), but didn't generate any
Excel spreadsheets with traffic light boxes, so management didn't like
it.
> And yes they tried to insist that everyone, even students, should change
> their passwords every month! We did get this altered so only passwords on
> admin and fincancial systems were covered. But the number of passwords on
> post-it-notes under keyboards, etc, mushroomed.
Yep. Depressing, isn't it? Still, I no longer have to GAS.
> (*) Pimply Faced Youth
*grin* I am entirely familiar with the Bastard Operator from Hell.
--
Today is Boomtime, the 16th day of Confusion in the YOLD 3185
Rising above bedlam
[toc] | [prev] | [next] | [standalone]
| From | Jerry Peters <jerry@example.invalid> |
|---|---|
| Date | 2019-06-12 00:10 +0000 |
| Message-ID | <qdpfti$gep$2@dont-email.me> |
| In reply to | #18179 |
Huge <Huge@nowhere.much.invalid> wrote: > On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote: >> On 3/06/2019 7:55 am, Rich wrote: >>> #################################################################### >>> # ATTENTION: This post is a reference to a website. The poster of # >>> # this Usenet article is not the author of the referenced website. # >>> #################################################################### >>> >>> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long- >>> live-your-passwords/> >>> >>> The text below is a quotation from the URL above: >>>> >>>> May was a momentous month, which marked a victory for sanity and >>>> pragmatism over irrational paranoia. I'm obviously not talking about >>>> politics. I'm talking about Microsoft finally - finally! but credit to >>>> them for doing this nonetheless! - removing the password expiration >>>> policies from their Windows 10 security baseline. >>>> >>>> Although NIST and others precede this and deserve that credit, I think >>>> it's worth taking a moment to recognize this moment in time as truly a >>>> fundamental change in the industry. >>>> >>>> - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019 >>>> >>>> Many enterprise-scale organizations (including TechCrunch's owner >>>> Verizon) require their users to change their passwords regularly. This >>>> is a spectacularly counterproductive policy. >>>> >>>> ... >> >> Why did this take so long? Why did so many people think it was a good >> idea to force password changes? > > Having spent many, many fruitless hours in shouty meetings with management, > trying to convince them that password changes are a stupid idea, the only > conclusion I can come to is that it's a religious matter. > I'm guessing auditors -- with a checklist, one item of which is: requires periodic password changes. The auditors probably got it from some seminar in the distant past and passed it around as received wisdom from then on.
[toc] | [prev] | [next] | [standalone]
| From | Huge <Huge@nowhere.much.invalid> |
|---|---|
| Date | 2019-06-12 08:50 +0000 |
| Message-ID | <gmbsmvFs9q8U2@mid.individual.net> |
| In reply to | #18193 |
On 2019-06-12, Jerry Peters <jerry@example.invalid> wrote:
> Huge <Huge@nowhere.much.invalid> wrote:
>> On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:
>>> On 3/06/2019 7:55 am, Rich wrote:
>>>> ####################################################################
>>>> # ATTENTION: This post is a reference to a website. The poster of #
>>>> # this Usenet article is not the author of the referenced website. #
>>>> ####################################################################
>>>>
>>>> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long-
>>>> live-your-passwords/>
>>>>
>>>> The text below is a quotation from the URL above:
>>>>>
>>>>> May was a momentous month, which marked a victory for sanity and
>>>>> pragmatism over irrational paranoia. I'm obviously not talking about
>>>>> politics. I'm talking about Microsoft finally - finally! but credit to
>>>>> them for doing this nonetheless! - removing the password expiration
>>>>> policies from their Windows 10 security baseline.
>>>>>
>>>>> Although NIST and others precede this and deserve that credit, I think
>>>>> it's worth taking a moment to recognize this moment in time as truly a
>>>>> fundamental change in the industry.
>>>>>
>>>>> - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019
>>>>>
>>>>> Many enterprise-scale organizations (including TechCrunch's owner
>>>>> Verizon) require their users to change their passwords regularly. This
>>>>> is a spectacularly counterproductive policy.
>>>>>
>>>>> ...
>>>
>>> Why did this take so long? Why did so many people think it was a good
>>> idea to force password changes?
>>
>> Having spent many, many fruitless hours in shouty meetings with management,
>> trying to convince them that password changes are a stupid idea, the only
>> conclusion I can come to is that it's a religious matter.
>>
> I'm guessing auditors -- with a checklist, one item of which is:
> requires periodic password changes.
> The auditors probably got it from some seminar in the distant past and
> passed it around as received wisdom from then on.
Almost certainly true.
--
Today is Pungenday, the 17th day of Confusion in the YOLD 3185
Rising above bedlam
[toc] | [prev] | [next] | [standalone]
| From | Rich <rich@example.invalid> |
|---|---|
| Date | 2019-06-11 11:03 +0000 |
| Message-ID | <qdo1qp$84h$1@dont-email.me> |
| In reply to | #18178 |
Sylvia Else <sylvia@email.invalid> wrote: > On 3/06/2019 7:55 am, Rich wrote: >> #################################################################### >> # ATTENTION: This post is a reference to a website. The poster of # >> # this Usenet article is not the author of the referenced website. # >> #################################################################### >> >> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long- >> live-your-passwords/> >> >> The text below is a quotation from the URL above: >>> >>> May was a momentous month, which marked a victory for sanity and >>> pragmatism over irrational paranoia. I'm obviously not talking about >>> politics. I'm talking about Microsoft finally - finally! but credit to >>> them for doing this nonetheless! - removing the password expiration >>> policies from their Windows 10 security baseline. >>> >>> Although NIST and others precede this and deserve that credit, I think >>> it's worth taking a moment to recognize this moment in time as truly a >>> fundamental change in the industry. >>> >>> - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019 >>> >>> Many enterprise-scale organizations (including TechCrunch's owner >>> Verizon) require their users to change their passwords regularly. This >>> is a spectacularly counterproductive policy. >>> >>> ... > > Why did this take so long? Security theater is *very* slow to change. > Why did so many people think it was a good idea to force password > changes? This is one likely explanation: https://themindunleashed.com/2016/02/the-famous-social-experiment-5-monkeys-and-a-ladder.html
[toc] | [prev] | [next] | [standalone]
| From | Sylvia Else <sylvia@email.invalid> |
|---|---|
| Date | 2019-06-11 21:55 +1000 |
| Message-ID | <gm9j54Fd0poU1@mid.individual.net> |
| In reply to | #18182 |
On 11/06/2019 9:03 pm, Rich wrote: > Sylvia Else <sylvia@email.invalid> wrote: >> On 3/06/2019 7:55 am, Rich wrote: >>> #################################################################### >>> # ATTENTION: This post is a reference to a website. The poster of # >>> # this Usenet article is not the author of the referenced website. # >>> #################################################################### >>> >>> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long- >>> live-your-passwords/> >>> >>> The text below is a quotation from the URL above: >>>> >>>> May was a momentous month, which marked a victory for sanity and >>>> pragmatism over irrational paranoia. I'm obviously not talking about >>>> politics. I'm talking about Microsoft finally - finally! but credit to >>>> them for doing this nonetheless! - removing the password expiration >>>> policies from their Windows 10 security baseline. >>>> >>>> Although NIST and others precede this and deserve that credit, I think >>>> it's worth taking a moment to recognize this moment in time as truly a >>>> fundamental change in the industry. >>>> >>>> - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019 >>>> >>>> Many enterprise-scale organizations (including TechCrunch's owner >>>> Verizon) require their users to change their passwords regularly. This >>>> is a spectacularly counterproductive policy. >>>> >>>> ... >> >> Why did this take so long? > > Security theater is *very* slow to change. > >> Why did so many people think it was a good idea to force password >> changes? > > This is one likely explanation: > > https://themindunleashed.com/2016/02/the-famous-social-experiment-5-monkeys-and-a-ladder.html > Perhaps that's also why I have to endure "music" at McDonalds. Presumably, the received wisdom is that it improves profits. I've repeatedly asked whether there's any evidence. If anyone knows, they're not saying. Sylvia.
[toc] | [prev] | [next] | [standalone]
| From | Huge <Huge@nowhere.much.invalid> |
|---|---|
| Date | 2019-06-11 15:30 +0000 |
| Message-ID | <gm9vonFfnf0U1@mid.individual.net> |
| In reply to | #18183 |
On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:
> On 11/06/2019 9:03 pm, Rich wrote:
>> Sylvia Else <sylvia@email.invalid> wrote:
[snip]
>>> Why did this take so long?
>>
>> Security theater is *very* slow to change.
>>
>>> Why did so many people think it was a good idea to force password
>>> changes?
>>
>> This is one likely explanation:
>>
>> https://themindunleashed.com/2016/02/the-famous-social-experiment-5-monkeys-and-a-ladder.html
It used to drive me crazy when people said of poor security practices
that "they'd always done it like that". My response, depending on mood,
was either "Well, you've always done it wrong, then", or, "we always
used to put children up chimneys and die of typhoid and cholera from
drinking water contaminated with our own shit. Do you want to carry on
doing *that*, too??"
> Perhaps that's also why I have to endure "music" at McDonalds.
> Presumably, the received wisdom is that it improves profits. I've
> repeatedly asked whether there's any evidence. If anyone knows, they're
> not saying.
*applause* Speaking as someone who regularly turns "music" off, or asks
for it to be turned off, and has been known to disconnect loudspeakers,
I couldn't agree more.
--
Today is Boomtime, the 16th day of Confusion in the YOLD 3185
Rising above bedlam
[toc] | [prev] | [next] | [standalone]
| From | Mike Spencer <mds@bogus.nodomain.nowhere> |
|---|---|
| Date | 2019-06-11 17:43 -0300 |
| Subject | Re: [Link Posting] Password expiration is dead, long live your passwords |
| Message-ID | <87zhmnq2e1.fsf@bogus.nodomain.nowhere> |
| In reply to | #18184 |
Huge <Huge@nowhere.much.invalid> writes: > It used to drive me crazy when people said of poor security practices > that "they'd always done it like that". My response, depending on mood, > was either "Well, you've always done it wrong, then", or, "we always > used to put children up chimneys and die of typhoid and cholera from > drinking water contaminated with our own shit. Do you want to carry on > doing *that*, too??" Sometimes there's a good explanation for "how we always done it", albeit not always a reason to continue doing it. In the 70s, I visited the "block shop" in Lunenburg, NS, where they made tackle blocks with methods and gear that was a century or more old -- everything from moby 4-sheave blocks for fishing gear to spiffy little teak & stainless items for yachts. Down in the cellar was a blacksmith shop where they forged the eyebolts, hooks and other metal parts. When I was there, the smith was making hooks. He split the end of a 1" dia. rod, bent the two ears of the split around a mandrel to overlap and form an eye and forge-welded them together. (Then the other end was forged into the hook.) I asked him why he was splitting and welding to form the eye when just hot-punching the hole would have been easier and given more predictable results. "Stronger this way, stronger this way." was all he had to say. It was weeks later that it dawned on me that he had learned how to forge hook eyes from his predecessor at the block shop, who had learned it from his, etc. back to when the place was built. And that reached back to the days before Bessemer, open hearth and cheap steel, the days when wrought iron was the article of commerce from which "iron" things were made. And he was absolutely right: Wrought iron has a macroscopic grain structure similar to wood. Punching a load-bearing eye near the end of a piece of wrought iron predisposes to failure similar to boring a hole near the end of a pine board and then using it as a tension member. Splitting, wrapping and welding (which you obviously can't do with wood) makes the grain run *around* the eye. The increase in strength and reliability far exceeds the risk of possible defects in the forge weld. So he was right, or rather, he had been right up to a point somewhere between 1890 and 1910. -- Mike Spencer Nova Scotia, Canada
[toc] | [prev] | [next] | [standalone]
| From | Huge <Huge@nowhere.much.invalid> |
|---|---|
| Date | 2019-06-12 08:58 +0000 |
| Subject | Re: [Link Posting] Password expiration is dead, long live your passwords |
| Message-ID | <gmbt5gFs9q8U6@mid.individual.net> |
| In reply to | #18190 |
On 2019-06-11, Mike Spencer <mds@bogus.nodomain.nowhere> wrote:
>
> Huge <Huge@nowhere.much.invalid> writes:
>
>> It used to drive me crazy when people said of poor security practices
>> that "they'd always done it like that". My response, depending on mood,
>> was either "Well, you've always done it wrong, then", or, "we always
>> used to put children up chimneys and die of typhoid and cholera from
>> drinking water contaminated with our own shit. Do you want to carry on
>> doing *that*, too??"
>
>
> Sometimes there's a good explanation for "how we always done it",
> albeit not always a reason to continue doing it.
Good point. And in a similar vein, the IT world is very fond of re-inventing
the wheel.
--
Today is Pungenday, the 17th day of Confusion in the YOLD 3185
Rising above bedlam
[toc] | [prev] | [next] | [standalone]
| From | kludge@panix.com (Scott Dorsey) |
|---|---|
| Date | 2019-06-11 21:14 -0400 |
| Message-ID | <qdpjl4$69q$1@panix2.panix.com> |
| In reply to | #18184 |
Huge <usenet@huge.org.uk> wrote: >On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote: > >> Perhaps that's also why I have to endure "music" at McDonalds. >> Presumably, the received wisdom is that it improves profits. I've >> repeatedly asked whether there's any evidence. If anyone knows, they're >> not saying. > >*applause* Speaking as someone who regularly turns "music" off, or asks >for it to be turned off, and has been known to disconnect loudspeakers, >I couldn't agree more. It is there to drive you away. Just like the way the chairs at McDonalds are designed to be uncomfortable. They want you to sit and eat but they don't want you to keep hanging around after you have eaten. The whole environment is designed to get you out so someone else can come in and pay for food. It improves profits. --scott -- "C'est un Nagra. C'est suisse, et tres, tres precis."
[toc] | [prev] | [next] | [standalone]
| From | Huge <Huge@nowhere.much.invalid> |
|---|---|
| Date | 2019-06-12 08:52 +0000 |
| Message-ID | <gmbspkFs9q8U3@mid.individual.net> |
| In reply to | #18195 |
On 2019-06-12, Scott Dorsey <kludge@panix.com> wrote:
> Huge <usenet@huge.org.uk> wrote:
>>On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:
>>
>>> Perhaps that's also why I have to endure "music" at McDonalds.
>>> Presumably, the received wisdom is that it improves profits. I've
>>> repeatedly asked whether there's any evidence. If anyone knows, they're
>>> not saying.
>>
>>*applause* Speaking as someone who regularly turns "music" off, or asks
>>for it to be turned off, and has been known to disconnect loudspeakers,
>>I couldn't agree more.
>
> It is there to drive you away. Just like the way the chairs at McDonalds
> are designed to be uncomfortable. They want you to sit and eat
Good luck with that. I sit and eat in a Mikkey D's about once a decade.
> but they
> don't want you to keep hanging around after you have eaten. The whole
> environment is designed to get you out so someone else can come in and
> pay for food. It improves profits.
But a good point, nonetheless.
--
Today is Pungenday, the 17th day of Confusion in the YOLD 3185
Rising above bedlam
[toc] | [prev] | [next] | [standalone]
| From | Sylvia Else <sylvia@email.invalid> |
|---|---|
| Date | 2019-06-15 11:45 +1000 |
| Message-ID | <gmj0tsFeoa9U1@mid.individual.net> |
| In reply to | #18195 |
On 12/06/2019 11:14 am, Scott Dorsey wrote: > Huge <usenet@huge.org.uk> wrote: >> On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote: >> >>> Perhaps that's also why I have to endure "music" at McDonalds. >>> Presumably, the received wisdom is that it improves profits. I've >>> repeatedly asked whether there's any evidence. If anyone knows, they're >>> not saying. >> >> *applause* Speaking as someone who regularly turns "music" off, or asks >> for it to be turned off, and has been known to disconnect loudspeakers, >> I couldn't agree more. > > It is there to drive you away. Just like the way the chairs at McDonalds > are designed to be uncomfortable. They want you to sit and eat but they > don't want you to keep hanging around after you have eaten. The whole > environment is designed to get you out so someone else can come in and > pay for food. It improves profits. > --scott > This may indeed be the thinking, but does it work? Was any experimenting done, or did someone just suppose that it would have that effect, and it's been in place ever since, annoying people for no useful purpose? Sylvia.
[toc] | [prev] | [next] | [standalone]
| From | kludge@panix.com (Scott Dorsey) |
|---|---|
| Date | 2019-06-15 15:46 -0400 |
| Message-ID | <qe3hul$e2p$1@panix2.panix.com> |
| In reply to | #18209 |
Sylvia Else <sylvia@email.invalid> wrote: >On 12/06/2019 11:14 am, Scott Dorsey wrote: >> >> It is there to drive you away. Just like the way the chairs at McDonalds >> are designed to be uncomfortable. They want you to sit and eat but they >> don't want you to keep hanging around after you have eaten. The whole >> environment is designed to get you out so someone else can come in and >> pay for food. It improves profits. > >This may indeed be the thinking, but does it work? Was any experimenting >done, or did someone just suppose that it would have that effect, and >it's been in place ever since, annoying people for no useful purpose? Yes, an extensive amount of testing is done. McDonalds has a rather large corporate organization devoted to researching this sort of stuff, and they employ an awful lot of experimental psych people. As an engineering undergraduate, I took an industrial and organizational psychology class with an adjunct professor who turned out to be one of the marketing guys at Coca-Cola. It was very interesting. --scott -- "C'est un Nagra. C'est suisse, et tres, tres precis."
[toc] | [prev] | [next] | [standalone]
| From | Kerry Imming <kcimming@pobox.com> |
|---|---|
| Date | 2019-06-11 12:19 -0500 |
| Message-ID | <qdonqh$f3g$1@dont-email.me> |
| In reply to | #18178 |
On 6/11/2019 1:42 AM, Sylvia Else wrote: > Why did this take so long? Why did so many people think it was a good > idea to force password changes? My thought was that it dated back to logging in to a command line (as described in Clifford Stoll's book, "The Cuckoo's Egg") vs. a web page. A hacker then had access to explore the system as long as no changes were made that would cause them to be detected. Changing the password would limit this exploration time. - Kerry
[toc] | [prev] | [next] | [standalone]
| From | Huge <Huge@nowhere.much.invalid> |
|---|---|
| Date | 2019-06-11 18:21 +0000 |
| Message-ID | <gma9ojFht61U2@mid.individual.net> |
| In reply to | #18185 |
On 2019-06-11, Kerry Imming <kcimming@pobox.com> wrote:
> On 6/11/2019 1:42 AM, Sylvia Else wrote:
>> Why did this take so long? Why did so many people think it was a good
>> idea to force password changes?
>
> My thought was that it dated back to logging in to a command line (as
> described in Clifford Stoll's book, "The Cuckoo's Egg") vs. a web page.
> A hacker then had access to explore the system as long as no changes
> were made that would cause them to be detected. Changing the password
> would limit this exploration time.
On a Unix system, once you're logged on, changing the logon password makes
no difference whatsoever (unless the user tries to use a tool which re-reads
the password, e.g. sudo).
Not sure your web analogy is very good, either.
--
Today is Boomtime, the 16th day of Confusion in the YOLD 3185
Rising above bedlam
[toc] | [prev] | [next] | [standalone]
| From | kludge@panix.com (Scott Dorsey) |
|---|---|
| Date | 2019-06-11 21:12 -0400 |
| Message-ID | <qdpjh2$olm$1@panix2.panix.com> |
| In reply to | #18178 |
Sylvia Else <sylvia@email.invalid> wrote: > >Why did this take so long? Why did so many people think it was a good >idea to force password changes? I can answer that question: because NIST told them it was a good idea. Now.... whatever made the NIST standards people ever think it was a good idea, that I cannot answer. --scott -- "C'est un Nagra. C'est suisse, et tres, tres precis."
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | comp.misc
csiph-web