Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.misc > #18101 > unrolled thread

[Link Posting] Password expiration is dead, long live your passwords

Started byRich <rich@example.invalid>
First post2019-06-02 21:55 +0000
Last post2019-06-11 21:12 -0400
Articles 20 on this page of 37 — 11 participants

Back to article view | Back to comp.misc


Contents

  [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-02 21:55 +0000
    Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-03 20:28 +0000
      Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-03 20:35 +0000
      Re: [Link Posting] Password expiration is dead, long live your passwords RS Wood <rsw@therandymon.com> - 2019-06-09 09:10 -0400
        Re: [Link Posting] Password expiration is dead, long live your passwords Richard Kettlewell <invalid@invalid.invalid> - 2019-06-09 14:22 +0100
          Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-09 14:39 +0000
        Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-09 20:33 +0000
          Re: [Link Posting] Password expiration is dead, long live your passwords ant@zimage.comANT (Ant) - 2019-06-10 11:22 -0500
          Re: [Link Posting] Password expiration is dead, long live your passwords Kerry Imming <kcimming@pobox.com> - 2019-06-10 11:42 -0500
            Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-10 18:05 +0000
            Re: [Link Posting] Password expiration is dead, long live your passwords Richard Kettlewell <invalid@invalid.invalid> - 2019-06-10 22:28 +0100
    Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-11 16:42 +1000
      Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 09:39 +0000
        Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-11 20:29 +1000
          Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 11:01 +0000
            Re: [Link Posting] Password expiration is dead, long live your  passwords Mike Spencer <mds@bogus.nodomain.nowhere> - 2019-06-11 17:18 -0300
              Re: [Link Posting] Password expiration is dead, long live your  passwords Jerry Peters <jerry@example.invalid> - 2019-06-12 00:04 +0000
                Re: [Link Posting] Password expiration is dead, long live your  passwords Mike Spencer <mds@bogus.nodomain.nowhere> - 2019-06-12 01:49 -0300
                Re: [Link Posting] Password expiration is dead, long live your  passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:49 +0000
              Re: [Link Posting] Password expiration is dead, long live your  passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:57 +0000
        Re: [Link Posting] Password expiration is dead, long live your passwords Jim Jackson <jj@franjam.org.uk> - 2019-06-11 17:57 +0000
          Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-11 18:05 +0000
          Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 21:08 +0000
        Re: [Link Posting] Password expiration is dead, long live your passwords Jerry Peters <jerry@example.invalid> - 2019-06-12 00:10 +0000
          Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:50 +0000
      Re: [Link Posting] Password expiration is dead, long live your passwords Rich <rich@example.invalid> - 2019-06-11 11:03 +0000
        Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-11 21:55 +1000
          Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 15:30 +0000
            Re: [Link Posting] Password expiration is dead, long live your  passwords Mike Spencer <mds@bogus.nodomain.nowhere> - 2019-06-11 17:43 -0300
              Re: [Link Posting] Password expiration is dead, long live your  passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:58 +0000
            Re: [Link Posting] Password expiration is dead, long live your passwords kludge@panix.com (Scott Dorsey) - 2019-06-11 21:14 -0400
              Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-12 08:52 +0000
              Re: [Link Posting] Password expiration is dead, long live your passwords Sylvia Else <sylvia@email.invalid> - 2019-06-15 11:45 +1000
                Re: [Link Posting] Password expiration is dead, long live your passwords kludge@panix.com (Scott Dorsey) - 2019-06-15 15:46 -0400
      Re: [Link Posting] Password expiration is dead, long live your passwords Kerry Imming <kcimming@pobox.com> - 2019-06-11 12:19 -0500
        Re: [Link Posting] Password expiration is dead, long live your passwords Huge <Huge@nowhere.much.invalid> - 2019-06-11 18:21 +0000
      Re: [Link Posting] Password expiration is dead, long live your passwords kludge@panix.com (Scott Dorsey) - 2019-06-11 21:12 -0400

Page 1 of 2  [1] 2  Next page →


#18101 — [Link Posting] Password expiration is dead, long live your passwords

FromRich <rich@example.invalid>
Date2019-06-02 21:55 +0000
Subject[Link Posting] Password expiration is dead, long live your passwords
Message-ID<MlpB1YKRhgDPsuv1m3oW7DKj@dont-email.me>
      ####################################################################
      # ATTENTION: This post is a reference to a website.  The poster of #
      # this Usenet article is not the author of the referenced website. #
      ####################################################################

<URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long-
live-your-passwords/>

The text below is a quotation from the URL above:
>
>  May was a momentous month, which marked a victory for sanity and
>  pragmatism over irrational paranoia. I'm obviously not talking about
>  politics. I'm talking about Microsoft finally - finally! but credit to
>  them for doing this nonetheless! - removing the password expiration
>  policies from their Windows 10 security baseline.
>
>  Although NIST and others precede this and deserve that credit, I think
>  it's worth taking a moment to recognize this moment in time as truly a
>  fundamental change in the industry.
>
>  - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019
>
>  Many enterprise-scale organizations (including TechCrunch's owner
>  Verizon) require their users to change their passwords regularly. This
>  is a spectacularly counterproductive policy.
>
>  ...

[toc] | [next] | [standalone]


#18104

FromJerry Peters <jerry@example.invalid>
Date2019-06-03 20:28 +0000
Message-ID<qd3vu5$ugf$1@dont-email.me>
In reply to#18101
Rich <rich@example.invalid> wrote:
>      ####################################################################
>      # ATTENTION: This post is a reference to a website.  The poster of #
>      # this Usenet article is not the author of the referenced website. #
>      ####################################################################
> 
> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long-
> live-your-passwords/>
> 
> The text below is a quotation from the URL above:
>>
>>  May was a momentous month, which marked a victory for sanity and
>>  pragmatism over irrational paranoia. I'm obviously not talking about
>>  politics. I'm talking about Microsoft finally - finally! but credit to
>>  them for doing this nonetheless! - removing the password expiration
>>  policies from their Windows 10 security baseline.
>>
>>  Although NIST and others precede this and deserve that credit, I think
>>  it's worth taking a moment to recognize this moment in time as truly a
>>  fundamental change in the industry.
>>
>>  - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019
>>
>>  Many enterprise-scale organizations (including TechCrunch's owner
>>  Verizon) require their users to change their passwords regularly. This
>>  is a spectacularly counterproductive policy.

Yes! When I had to change my passwords monthly I kept a circular list
& resused the oldest password, IIRC the system kept the most recent 12
passwords to prevent reuse. A co-worker used the same password but
added a numeric suffix to get around the policy.

[toc] | [prev] | [next] | [standalone]


#18105

FromRich <rich@example.invalid>
Date2019-06-03 20:35 +0000
Message-ID<qd409n$pmh$3@dont-email.me>
In reply to#18104
Jerry Peters <jerry@example.invalid> wrote:
> Rich <rich@example.invalid> wrote:
>> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long-
>> live-your-passwords/>
>> 
>> The text below is a quotation from the URL above:
>>>
>>>  politics. I'm talking about Microsoft finally - finally! but credit to
>>>  them for doing this nonetheless! - removing the password expiration
>>>  policies from their Windows 10 security baseline.
>>>
>>>  Although NIST and others precede this and deserve that credit, I think
>>>  it's worth taking a moment to recognize this moment in time as truly a
>>>  fundamental change in the industry.
> 
> Yes! When I had to change my passwords monthly I kept a circular list
> & resused the oldest password, IIRC the system kept the most recent 12
> passwords to prevent reuse. A co-worker used the same password but
> added a numeric suffix to get around the policy.

The problem will be that /policy/ changes slowly, so it will likely be 
many years before all entities finally drop their requirements to 
change passwords on some periodic basis.

So your circular list of X passwords will likely be useful for quite 
some time.

[toc] | [prev] | [next] | [standalone]


#18150

FromRS Wood <rsw@therandymon.com>
Date2019-06-09 09:10 -0400
Message-ID<qdj0dn$2a2$1@solani.org>
In reply to#18104
Jerry Peters <jerry@example.invalid> Wrote in message:
> Rich <rich@example.invalid> wrote:>.


Here's the money quote:

If you have a password at such an organization, I recommend you
 send that blog post to its system administrators. They will
 ignore you at first, of course, because that’s what enterprise
 administrators do, and because information security (like
 transportation security) is too often an irrational one-way
 ratchet because our culture of fear incentivizes security theater
 rather than actual security — but they may grudgingly begin to
 accept that the world has moved on.

-- 

[toc] | [prev] | [next] | [standalone]


#18151

FromRichard Kettlewell <invalid@invalid.invalid>
Date2019-06-09 14:22 +0100
Message-ID<87k1duzyf0.fsf@LkoBDZeT.terraraq.uk>
In reply to#18150
RS Wood <rsw@therandymon.com> writes:
> Here's the money quote:
>
> If you have a password at such an organization, I recommend you
>  send that blog post to its system administrators. They will
>  ignore you at first, of course, because that’s what enterprise
>  administrators do, and because information security (like
>  transportation security) is too often an irrational one-way
>  ratchet because our culture of fear incentivizes security theater
>  rather than actual security — but they may grudgingly begin to
>  accept that the world has moved on.

Enterprise system administrators do not make that decision, they merely
implement it (and deal with the fallout).

In some local IT management will make it; in other cases it will be
regulators, auditors or even customers.

-- 
https://www.greenend.org.uk/rjk/

[toc] | [prev] | [next] | [standalone]


#18155

FromRich <rich@example.invalid>
Date2019-06-09 14:39 +0000
Message-ID<qdj5nv$5d2$2@dont-email.me>
In reply to#18151
Richard Kettlewell <invalid@invalid.invalid> wrote:
> RS Wood <rsw@therandymon.com> writes:
>> Here's the money quote:
>>
>> If you have a password at such an organization, I recommend you
>>  send that blog post to its system administrators. They will
>>  ignore you at first, of course, because that?s what enterprise
>>  administrators do, and because information security (like
>>  transportation security) is too often an irrational one-way
>>  ratchet because our culture of fear incentivizes security theater
>>  rather than actual security ? but they may grudgingly begin to
>>  accept that the world has moved on.
> 
> Enterprise system administrators do not make that decision, they merely
> implement it (and deal with the fallout).

Correct.  Enterprise sys. admins are mostly "box checkers".

They are given a long checklist of requirements they must meet.  And 
they simply turn on whatever is necessary to be able to "check the box" 
for their quartery reports upwards in the management chain.

They do not even, usually, have the faintest idea of what is or is not 
secure, nor why.  They just make sure their systems "check off the 
boxes".

So to make any change, the blog post has to be mailed to whomever is 
creating the checklist the admins are expected to follow.  And then 
that person's irrational fears have to finally be quelled enough that 
they remove the "must change password every 60 days" requirement.

[toc] | [prev] | [next] | [standalone]


#18157

FromJerry Peters <jerry@example.invalid>
Date2019-06-09 20:33 +0000
Message-ID<qdjqes$p6g$1@dont-email.me>
In reply to#18150
RS Wood <rsw@therandymon.com> wrote:
> Jerry Peters <jerry@example.invalid> Wrote in message:
>> Rich <rich@example.invalid> wrote:>.
> 
> 
> Here's the money quote:
> 
> If you have a password at such an organization, I recommend you
> send that blog post to its system administrators. They will
> ignore you at first, of course, because that?s what enterprise
> administrators do, and because information security (like
> transportation security) is too often an irrational one-way
> ratchet because our culture of fear incentivizes security theater
> rather than actual security ? but they may grudgingly begin to
> accept that the world has moved on.
> 

A bank I *used* to deal with required that you change your online
password every 3 months. When I closed my accounts there I explained
that that was a *major* reason why I was leaving. That and their web
banking system was awful. 

I use KeepassX which keeps track of passwords and the various
questions for password reset. It also generates nicely random
passwords meeting whatever requirements they have, assuming the site
tells you what they expect in a password.

[toc] | [prev] | [next] | [standalone]


#18172

Fromant@zimage.comANT (Ant)
Date2019-06-10 11:22 -0500
Message-ID<wNadnQPVdK4hHmPBnZ2dnUU7-I2dnZ2d@earthlink.com>
In reply to#18157
Jerry Peters <jerry@example.invalid> wrote:

> A bank I *used* to deal with required that you change your online
> password every 3 months. When I closed my accounts there I explained
> that that was a *major* reason why I was leaving. That and their web
> banking system was awful. 

Which bank was that so we can avoid it?
-- 
Quote of the Week: "But, you may argue, our uniqueness is so extreme! 
More extreme than the platypus which looks like a collection of leftover 
parts? More unique than the societal honeybee with its division of 
labor? More unique than the communist ants who keep aphids as farm 
animals?" --John Logan
Note: A fixed width font (Courier, Monospace, etc.) is required to see this signature correctly.
  /\___/\   Ant(Dude) @ http://aqfl.net & http://antfarm.home.dhs.org /
 / /\ /\ \ http://antfarm.ma.cx. Please nuke ANT if replying by e-mail.
| |o   o| |
   \ _ /
    ( )

[toc] | [prev] | [next] | [standalone]


#18173

FromKerry Imming <kcimming@pobox.com>
Date2019-06-10 11:42 -0500
Message-ID<qdm19c$9sm$1@dont-email.me>
In reply to#18157
On 6/9/2019 3:33 PM, Jerry Peters wrote:
> RS Wood <rsw@therandymon.com> wrote:
>> Jerry Peters <jerry@example.invalid> Wrote in message:
>>> Rich <rich@example.invalid> wrote:>.
>>
>>
>> Here's the money quote:
>>
>> If you have a password at such an organization, I recommend you
>> send that blog post to its system administrators. They will
>> ignore you at first, of course, because that?s what enterprise
>> administrators do, and because information security (like
>> transportation security) is too often an irrational one-way
>> ratchet because our culture of fear incentivizes security theater
>> rather than actual security ? but they may grudgingly begin to
>> accept that the world has moved on.
>>
> 
> A bank I *used* to deal with required that you change your online
> password every 3 months. When I closed my accounts there I explained
> that that was a *major* reason why I was leaving. That and their web
> banking system was awful.
> 
> I use KeepassX which keeps track of passwords and the various
> questions for password reset. It also generates nicely random
> passwords meeting whatever requirements they have, assuming the site
> tells you what they expect in a password.
> 

This is the part I don't get.  Are individual accounts getting hacked 
routinely and we just don't hear about it?   It seems hackers are always 
interested in the system database and not wasting their time on a lousy 
individual account.

- Kerry

[toc] | [prev] | [next] | [standalone]


#18175

FromRich <rich@example.invalid>
Date2019-06-10 18:05 +0000
Message-ID<qdm65r$4t6$1@dont-email.me>
In reply to#18173
Kerry Imming <kcimming@pobox.com> wrote:
> On 6/9/2019 3:33 PM, Jerry Peters wrote:
>> A bank I *used* to deal with required that you change your online 
>> password every 3 months.  When I closed my accounts there I 
>> explained that that was a *major* reason why I was leaving.  That 
>> and their web banking system was awful.
>> 
> This is the part I don't get.  Are individual accounts getting hacked 
> routinely and we just don't hear about it?  It seems hackers are 
> always interested in the system database and not wasting their time 
> on a lousy individual account.

Security theater items are a lot like taxes.  They get added on top, 
but they seldom ever get removed later.

At one point, in the very distant past, maybe attacks were being made 
against individual users, by trying to brute force login to (say) a 
bank website as that user.

At that time, maybe password expiration policies *might* have made some 
sense, but even then I don't think so.  Lets say I change my password 
on June 1 because that is when it expired.  If a hacker manages to 
guess it on June 2, the expiration policy did me zero good from a 
security perspective.

Reality is that the world of attacks has moved on.  Few (beyond script 
kiddies) are trying to guess passwords by plural login attempts to 
website login pages.  As you point out, they are attacking the back-end 
DB system, which would give them access to everything, not just one 
user.

But because of the "add to the top, but never take away" mentality of 
security theater, we still have password expiration policies long after 
they became nothing more than user annoyances.

[toc] | [prev] | [next] | [standalone]


#18177

FromRichard Kettlewell <invalid@invalid.invalid>
Date2019-06-10 22:28 +0100
Message-ID<87blz5yvt6.fsf@LkoBDZeT.terraraq.uk>
In reply to#18173
Kerry Imming <kcimming@pobox.com> writes:
> This is the part I don't get.  Are individual accounts getting hacked
> routinely and we just don't hear about it?   It seems hackers are
> always interested in the system database and not wasting their time on
> a lousy individual account.

You shouldn’t expect to hear about them all, any more than you hear
about every other single-victim crime. One person being hacked is almost
never news, both because the impact is small and because it happens all
the time.

An entire enterprise being compromised, with hundreds of thousand or
millions of victims, is another story entirely.

-- 
https://www.greenend.org.uk/rjk/

[toc] | [prev] | [next] | [standalone]


#18178

FromSylvia Else <sylvia@email.invalid>
Date2019-06-11 16:42 +1000
Message-ID<gm90qvF97g1U1@mid.individual.net>
In reply to#18101
On 3/06/2019 7:55 am, Rich wrote:
>        ####################################################################
>        # ATTENTION: This post is a reference to a website.  The poster of #
>        # this Usenet article is not the author of the referenced website. #
>        ####################################################################
> 
> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long-
> live-your-passwords/>
> 
> The text below is a quotation from the URL above:
>>
>>   May was a momentous month, which marked a victory for sanity and
>>   pragmatism over irrational paranoia. I'm obviously not talking about
>>   politics. I'm talking about Microsoft finally - finally! but credit to
>>   them for doing this nonetheless! - removing the password expiration
>>   policies from their Windows 10 security baseline.
>>
>>   Although NIST and others precede this and deserve that credit, I think
>>   it's worth taking a moment to recognize this moment in time as truly a
>>   fundamental change in the industry.
>>
>>   - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019
>>
>>   Many enterprise-scale organizations (including TechCrunch's owner
>>   Verizon) require their users to change their passwords regularly. This
>>   is a spectacularly counterproductive policy.
>>
>>   ...

Why did this take so long? Why did so many people think it was a good 
idea to force password changes?

Sylvia.

[toc] | [prev] | [next] | [standalone]


#18179

FromHuge <Huge@nowhere.much.invalid>
Date2019-06-11 09:39 +0000
Message-ID<gm9b6cFbbonU2@mid.individual.net>
In reply to#18178
On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:
> On 3/06/2019 7:55 am, Rich wrote:
>>        ####################################################################
>>        # ATTENTION: This post is a reference to a website.  The poster of #
>>        # this Usenet article is not the author of the referenced website. #
>>        ####################################################################
>> 
>> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long-
>> live-your-passwords/>
>> 
>> The text below is a quotation from the URL above:
>>>
>>>   May was a momentous month, which marked a victory for sanity and
>>>   pragmatism over irrational paranoia. I'm obviously not talking about
>>>   politics. I'm talking about Microsoft finally - finally! but credit to
>>>   them for doing this nonetheless! - removing the password expiration
>>>   policies from their Windows 10 security baseline.
>>>
>>>   Although NIST and others precede this and deserve that credit, I think
>>>   it's worth taking a moment to recognize this moment in time as truly a
>>>   fundamental change in the industry.
>>>
>>>   - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019
>>>
>>>   Many enterprise-scale organizations (including TechCrunch's owner
>>>   Verizon) require their users to change their passwords regularly. This
>>>   is a spectacularly counterproductive policy.
>>>
>>>   ...
>
> Why did this take so long? Why did so many people think it was a good 
> idea to force password changes?

Having spent many, many fruitless hours in shouty meetings with management,
trying to convince them that password changes are a stupid idea, the only
conclusion I can come to is that it's a religious matter.

-- 
Today is Boomtime, the 16th day of Confusion in the YOLD 3185
                  Rising above bedlam

[toc] | [prev] | [next] | [standalone]


#18180

FromSylvia Else <sylvia@email.invalid>
Date2019-06-11 20:29 +1000
Message-ID<gm9e3mFbvibU1@mid.individual.net>
In reply to#18179
On 11/06/2019 7:39 pm, Huge wrote:
> On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:
>> On 3/06/2019 7:55 am, Rich wrote:
>>>         ####################################################################
>>>         # ATTENTION: This post is a reference to a website.  The poster of #
>>>         # this Usenet article is not the author of the referenced website. #
>>>         ####################################################################
>>>
>>> <URL:https://techcrunch.com/2019/06/02/password-expiration-is-dead-long-
>>> live-your-passwords/>
>>>
>>> The text below is a quotation from the URL above:
>>>>
>>>>    May was a momentous month, which marked a victory for sanity and
>>>>    pragmatism over irrational paranoia. I'm obviously not talking about
>>>>    politics. I'm talking about Microsoft finally - finally! but credit to
>>>>    them for doing this nonetheless! - removing the password expiration
>>>>    policies from their Windows 10 security baseline.
>>>>
>>>>    Although NIST and others precede this and deserve that credit, I think
>>>>    it's worth taking a moment to recognize this moment in time as truly a
>>>>    fundamental change in the industry.
>>>>
>>>>    - SwiftOnSecurity (@SwiftOnSecurity) May 31, 2019
>>>>
>>>>    Many enterprise-scale organizations (including TechCrunch's owner
>>>>    Verizon) require their users to change their passwords regularly. This
>>>>    is a spectacularly counterproductive policy.
>>>>
>>>>    ...
>>
>> Why did this take so long? Why did so many people think it was a good
>> idea to force password changes?
> 
> Having spent many, many fruitless hours in shouty meetings with management,
> trying to convince them that password changes are a stupid idea, the only
> conclusion I can come to is that it's a religious matter.
> 

Grrr! Don't talk to me about management.

Sometimes a lack of capacity for logical thought seems to be a job 
requirement.

Sylvia.

[toc] | [prev] | [next] | [standalone]


#18181

FromHuge <Huge@nowhere.much.invalid>
Date2019-06-11 11:01 +0000
Message-ID<gm9g0rFcb3mU1@mid.individual.net>
In reply to#18180
On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:
> On 11/06/2019 7:39 pm, Huge wrote:
>> On 2019-06-11, Sylvia Else <sylvia@email.invalid> wrote:

[snip]

>>> Why did this take so long? Why did so many people think it was a good
>>> idea to force password changes?
>> 
>> Having spent many, many fruitless hours in shouty meetings with management,
>> trying to convince them that password changes are a stupid idea, the only
>> conclusion I can come to is that it's a religious matter.
>> 
>
> Grrr! Don't talk to me about management.
>
> Sometimes a lack of capacity for logical thought seems to be a job 
> requirement.

Generally speaking, management get to where they are by being "good"
politicians (if there can be said to be any such thing) rather than
by being good engineers.

-- 
Today is Boomtime, the 16th day of Confusion in the YOLD 3185
                  Rising above bedlam

[toc] | [prev] | [next] | [standalone]


#18189 — Re: [Link Posting] Password expiration is dead, long live your passwords

FromMike Spencer <mds@bogus.nodomain.nowhere>
Date2019-06-11 17:18 -0300
SubjectRe: [Link Posting] Password expiration is dead, long live your passwords
Message-ID<874l4vri4j.fsf@bogus.nodomain.nowhere>
In reply to#18181
Huge <Huge@nowhere.much.invalid> writes:

> Generally speaking, management get to where they are by being "good"
> politicians (if there can be said to be any such thing) rather than
> by being good engineers.

In the '80s & '90s I was doing annual blacksmithing seminars for a
particular freshman program at MIT and  spent time chatting with the
humanities prof who ran it.  He reported, with some puzzlement, that
many of his students had said (words to the effect that) "I'm just
here majoring in $STEM-WHATEVER because I'm good at it. So I'll have
to serve out a couple of years after graduation doing $STEM-WHATEVER.
But what I really want is management because that's where the money
is."

The same professor also said "Lots of these kids are so bright it's
scary."

Dunno what happens when you put those two observations together.


-- 
Mike Spencer                  Nova Scotia, Canada

[toc] | [prev] | [next] | [standalone]


#18192 — Re: [Link Posting] Password expiration is dead, long live your passwords

FromJerry Peters <jerry@example.invalid>
Date2019-06-12 00:04 +0000
SubjectRe: [Link Posting] Password expiration is dead, long live your passwords
Message-ID<qdpfhq$gep$1@dont-email.me>
In reply to#18189
Mike Spencer <mds@bogus.nodomain.nowhere> wrote:
> 
> Huge <Huge@nowhere.much.invalid> writes:
> 
>> Generally speaking, management get to where they are by being "good"
>> politicians (if there can be said to be any such thing) rather than
>> by being good engineers.
> 
> In the '80s & '90s I was doing annual blacksmithing seminars for a
> particular freshman program at MIT and  spent time chatting with the
> humanities prof who ran it.  He reported, with some puzzlement, that
> many of his students had said (words to the effect that) "I'm just
> here majoring in $STEM-WHATEVER because I'm good at it. So I'll have
> to serve out a couple of years after graduation doing $STEM-WHATEVER.
> But what I really want is management because that's where the money
> is."
> 
> The same professor also said "Lots of these kids are so bright it's
> scary."
> 
> Dunno what happens when you put those two observations together.
> 
See N N Taleb: IYI -- intellectual yet idiot. 
https://medium.com/incerto/the-intellectual-yet-idiot-13211e2d0577#.6ot3305bl

[toc] | [prev] | [next] | [standalone]


#18196 — Re: [Link Posting] Password expiration is dead, long live your passwords

FromMike Spencer <mds@bogus.nodomain.nowhere>
Date2019-06-12 01:49 -0300
SubjectRe: [Link Posting] Password expiration is dead, long live your passwords
Message-ID<87v9xbpfvn.fsf@bogus.nodomain.nowhere>
In reply to#18192
Jerry Peters <jerry@example.invalid> writes:

> Mike Spencer <mds@bogus.nodomain.nowhere> wrote:
> 
>> Huge <Huge@nowhere.much.invalid> writes:
>> 
>>> Generally speaking, management get to where they are by being "good"
>>> politicians (if there can be said to be any such thing) rather than
>>> by being good engineers.
>> 
>> In the '80s & '90s I was doing annual blacksmithing seminars for a
>> particular freshman program at MIT and  spent time chatting with the
>> humanities prof who ran it.  He reported, with some puzzlement, that
>> many of his students had said (words to the effect that) "I'm just
>> here majoring in $STEM-WHATEVER because I'm good at it. So I'll have
>> to serve out a couple of years after graduation doing $STEM-WHATEVER.
>> But what I really want is management because that's where the money
>> is."
>> 
>> The same professor also said "Lots of these kids are so bright it's
>> scary."
>> 
>> Dunno what happens when you put those two observations together.
> 
> See N N Taleb: IYI -- intellectual yet idiot. 
> https://medium.com/incerto/the-intellectual-yet-idiot-13211e2d0577#.6ot3305bl

Thanks for that.  Interesting and entertaining harangue.  Too bad he
doesn't write better.

He complains:

       From the reactions to this piece, I discovered that the IYI has
       difficulty, when reading, in differentiating between the
       satirical and the literal.

He should work on clarity.  I've read a lot of arcane stuff,
understood much of it and remember, despite my years, quite a lot.[1]
So I hadda google to see why I'd never heard of the authors that the
putative IYI has "never read".  Oh, uh-huh: All the hits on "Libanius
Antiochus" are quoting or commenting on his article (or some kind of
click-scam pages).  Right, satire.  Only he can't quite make it work.

I probably won't buy the book.  But thanks anyhow. :-)



[1] Who's Arnold Snarb?  

-- 
Mike Spencer                  Nova Scotia, Canada

[toc] | [prev] | [next] | [standalone]


#18197 — Re: [Link Posting] Password expiration is dead, long live your passwords

FromHuge <Huge@nowhere.much.invalid>
Date2019-06-12 08:49 +0000
SubjectRe: [Link Posting] Password expiration is dead, long live your passwords
Message-ID<gmbskrFs9q8U1@mid.individual.net>
In reply to#18192
On 2019-06-12, Jerry Peters <jerry@example.invalid> wrote:
> Mike Spencer <mds@bogus.nodomain.nowhere> wrote:
>> 
>> Huge <Huge@nowhere.much.invalid> writes:
>> 
>>> Generally speaking, management get to where they are by being "good"
>>> politicians (if there can be said to be any such thing) rather than
>>> by being good engineers.
>> 
>> In the '80s & '90s I was doing annual blacksmithing seminars for a
>> particular freshman program at MIT and  spent time chatting with the
>> humanities prof who ran it.  He reported, with some puzzlement, that
>> many of his students had said (words to the effect that) "I'm just
>> here majoring in $STEM-WHATEVER because I'm good at it. So I'll have
>> to serve out a couple of years after graduation doing $STEM-WHATEVER.
>> But what I really want is management because that's where the money
>> is."
>> 
>> The same professor also said "Lots of these kids are so bright it's
>> scary."
>> 
>> Dunno what happens when you put those two observations together.
>> 
> See N N Taleb: IYI -- intellectual yet idiot. 
> https://medium.com/incerto/the-intellectual-yet-idiot-13211e2d0577#.6ot3305bl

What a sad, bitter little man.


-- 
Today is Pungenday, the 17th day of Confusion in the YOLD 3185
                  Rising above bedlam

[toc] | [prev] | [next] | [standalone]


#18200 — Re: [Link Posting] Password expiration is dead, long live your passwords

FromHuge <Huge@nowhere.much.invalid>
Date2019-06-12 08:57 +0000
SubjectRe: [Link Posting] Password expiration is dead, long live your passwords
Message-ID<gmbt39Fs9q8U5@mid.individual.net>
In reply to#18189
On 2019-06-11, Mike Spencer <mds@bogus.nodomain.nowhere> wrote:
>
> Huge <Huge@nowhere.much.invalid> writes:
>
>> Generally speaking, management get to where they are by being "good"
>> politicians (if there can be said to be any such thing) rather than
>> by being good engineers.
>
> In the '80s & '90s I was doing annual blacksmithing seminars for a
> particular freshman program at MIT and  spent time chatting with the
> humanities prof who ran it.  He reported, with some puzzlement, that
> many of his students had said (words to the effect that) "I'm just
> here majoring in $STEM-WHATEVER because I'm good at it. So I'll have
> to serve out a couple of years after graduation doing $STEM-WHATEVER.
> But what I really want is management because that's where the money
> is."

OTOH, that's the exact opposite of what I wanted. Because I was good
at the techy stuff, they kept trying to make me a manager. Yuck. I
hated it, was useless at it and pointless make-work like signing off
overtime sheets and approving expenses meant I didn't have time to
do the stuff I enjoyed and was good at.

> The same professor also said "Lots of these kids are so bright it's
> scary."
>
> Dunno what happens when you put those two observations together.

Me neither, since most of the middle managers I ever had were dumber
than rocks, IT degrees or not.


-- 
Today is Pungenday, the 17th day of Confusion in the YOLD 3185
                  Rising above bedlam

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | comp.misc


csiph-web