I won’t say where I work but we have strict password requirements including that they have to be exactly 8 characters long.
Yeah our passwords aren’t very secure as we also have to change them every 90 days and if you miss the window by 3 days you have to call the IT desk to reset it which takes about 45 minutes to an hour. And in that time you basically can’t get anything done.
At home I use a password manager and all my passwords are randomly generated and whenever possible 2fa is enabled.
Not sure if you’re in the US. But if you are, you should leave this anonymously on the security team’s desks.
> Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator. - NIST control SP 800-63B Section 5.1.1.2
Basically a fairly widespread standard of security. All kinda of complaince you can fall out of if you do business with anyone who cares about NIST controls.
deleted by creator
Or use a fucking password manager like Bitwarden or Keepass
I won’t say where I work but we have strict password requirements including that they have to be exactly 8 characters long.
Yeah our passwords aren’t very secure as we also have to change them every 90 days and if you miss the window by 3 days you have to call the IT desk to reset it which takes about 45 minutes to an hour. And in that time you basically can’t get anything done.
At home I use a password manager and all my passwords are randomly generated and whenever possible 2fa is enabled.
Not sure if you’re in the US. But if you are, you should leave this anonymously on the security team’s desks.
> Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator. - NIST control SP 800-63B Section 5.1.1.2
Basically a fairly widespread standard of security. All kinda of complaince you can fall out of if you do business with anyone who cares about NIST controls.
I do. This still happens to me regularly. Companies love to fuck with their password algorithms way too much.