• 0 Posts
  • 6 Comments
Joined 2 years ago
cake
Cake day: June 20th, 2023

help-circle

  • FWIW: these types of password rules are discouraged by NIST -

    1. Eliminate Periodic Resets

    Many companies ask their users to reset their passwords every few months, thinking that any unauthorized person who obtained a user’s password will soon be locked out. However, frequent password changes can actually make security worse.

    It’s difficult enough to remember one good password a year. And since users often have numerous passwords to remember already, they often resort to changing their passwords in predictable patterns, such as adding a single character to the end of their last password or replacing a letter with a symbol that looks like it (such as $ instead of S).

    So if an attacker already knows a user’s previous password, it won’t be difficult to crack the new one. The NIST guidelines state that periodic password-change requirements should be removed for this reason.


  • The sad truth is it will need to get much worse until conservatives will admit there is a problem and let progressives solve it.

    It has always been this way. You either live in a progressive, upwardly moving state with improving quality of life or you get stuck in a conservative, stagnant or downward trending place where people are more concerned with “others” than they are with doing anything productive as a society. As a species, we seem to slowly wobble back and forth between these extremes. It’s maddening.