β² 1094 βΌ Incorrect Password (media.piefed.world) submitted 3 months ago by negativenull@piefed.world to c/comicstrips@lemmy.world 78 comments fedilink hide all child comments source
[β] FelixCress@lemmy.world 7 points 3 months ago (2 children) Fuck the cyber idiots and their "change password" requirements. permalink fedilink source hideshow 4 child comments replies: [β] fenrrs@lemmy.world 15 points 3 months ago (1 child) Current best practice in cybersecurity is to not arbitrarily ask users to change passwords every x days, so any site doing this are following old guidelines. permalink fedilink source parent hideshow 2 child comments replies: [β] dual_sport_dork@lemmy.world 12 points 3 months ago (1 child) Yes, because among other things this annoys users into just writing down their password on a Post-It and sticking it to the bottom of their keyboard or monitor ripe for any passerby to take. I have explained this to various management types repeatedly over the decades and nobody seems to get it. permalink fedilink source parent hideshow 2 child comments replies: [β] NaibofTabr@infosec.pub 7 points 3 months ago (1 child) I've had success directing people to the NIST password policy guidance. permalink fedilink source parent hideshow 2 child comments replies: [β] Draegur@lemmy.zip 3 points 3 months ago (1 child) Wow it's almost as though somebody in there reads xkcd and knows about correct horse battery staple! permalink fedilink source parent hideshow 2 child comments replies: [β] NaibofTabr@infosec.pub 3 points 3 months ago The folks at NIST know what they're talking about. The US government directed them to develop security policy for government information systems in 2002 (FISMA) - they've been thinking about how to do this properly for 24 years. If you happen to work for a US government agency of any kind, you can basically tell your boss "NIST guidance says we should do X" and compliance is technically required by law (within the context of security policies that apply to your agency's work area). If you work for a company that does business with the US government, there are similar compliance policies also published by NIST that you should be following (and your company could lose its contracts if it is not compliant). permalink fedilink source parent [β] negativenull@piefed.world [S] 8 points 3 months ago (1 child) Static password with good 2FA is the way to go. permalink fedilink source parent hideshow 2 child comments replies: [β] mrsemi@lemmy.world 7 points 3 months ago* (1 child) I ran into some app a while back that required 2fa "text you a code" to log in every time. If you put in the wrong password, it still sent you the 2fa... Which it would accept for login. I'm honestly not sure if it ever even checked the password. permalink fedilink source parent hideshow 2 child comments replies: [β] negativenull@piefed.world [S] 5 points 3 months ago (1 child) I've seen an increase of sites that bypass passwords altogether and rely on 2fa (claude.ai was one I noticed the otherday) permalink fedilink source parent hideshow 2 child comments replies: [β] dual_sport_dork@lemmy.world 10 points 3 months ago (1 child) That's... not 2FA anymore. It's reverted to 1FA, now with sprinkles on it. permalink fedilink source parent hideshow 2 child comments replies: [β] jaybone@lemmy.zip 3 points 3 months ago Those arenβt sprinkles. permalink fedilink source parent
[β] fenrrs@lemmy.world 15 points 3 months ago (1 child) Current best practice in cybersecurity is to not arbitrarily ask users to change passwords every x days, so any site doing this are following old guidelines. permalink fedilink source parent hideshow 2 child comments replies: [β] dual_sport_dork@lemmy.world 12 points 3 months ago (1 child) Yes, because among other things this annoys users into just writing down their password on a Post-It and sticking it to the bottom of their keyboard or monitor ripe for any passerby to take. I have explained this to various management types repeatedly over the decades and nobody seems to get it. permalink fedilink source parent hideshow 2 child comments replies: [β] NaibofTabr@infosec.pub 7 points 3 months ago (1 child) I've had success directing people to the NIST password policy guidance. permalink fedilink source parent hideshow 2 child comments replies: [β] Draegur@lemmy.zip 3 points 3 months ago (1 child) Wow it's almost as though somebody in there reads xkcd and knows about correct horse battery staple! permalink fedilink source parent hideshow 2 child comments replies: [β] NaibofTabr@infosec.pub 3 points 3 months ago The folks at NIST know what they're talking about. The US government directed them to develop security policy for government information systems in 2002 (FISMA) - they've been thinking about how to do this properly for 24 years. If you happen to work for a US government agency of any kind, you can basically tell your boss "NIST guidance says we should do X" and compliance is technically required by law (within the context of security policies that apply to your agency's work area). If you work for a company that does business with the US government, there are similar compliance policies also published by NIST that you should be following (and your company could lose its contracts if it is not compliant). permalink fedilink source parent
[β] dual_sport_dork@lemmy.world 12 points 3 months ago (1 child) Yes, because among other things this annoys users into just writing down their password on a Post-It and sticking it to the bottom of their keyboard or monitor ripe for any passerby to take. I have explained this to various management types repeatedly over the decades and nobody seems to get it. permalink fedilink source parent hideshow 2 child comments replies: [β] NaibofTabr@infosec.pub 7 points 3 months ago (1 child) I've had success directing people to the NIST password policy guidance. permalink fedilink source parent hideshow 2 child comments replies: [β] Draegur@lemmy.zip 3 points 3 months ago (1 child) Wow it's almost as though somebody in there reads xkcd and knows about correct horse battery staple! permalink fedilink source parent hideshow 2 child comments replies: [β] NaibofTabr@infosec.pub 3 points 3 months ago The folks at NIST know what they're talking about. The US government directed them to develop security policy for government information systems in 2002 (FISMA) - they've been thinking about how to do this properly for 24 years. If you happen to work for a US government agency of any kind, you can basically tell your boss "NIST guidance says we should do X" and compliance is technically required by law (within the context of security policies that apply to your agency's work area). If you work for a company that does business with the US government, there are similar compliance policies also published by NIST that you should be following (and your company could lose its contracts if it is not compliant). permalink fedilink source parent
[β] NaibofTabr@infosec.pub 7 points 3 months ago (1 child) I've had success directing people to the NIST password policy guidance. permalink fedilink source parent hideshow 2 child comments replies: [β] Draegur@lemmy.zip 3 points 3 months ago (1 child) Wow it's almost as though somebody in there reads xkcd and knows about correct horse battery staple! permalink fedilink source parent hideshow 2 child comments replies: [β] NaibofTabr@infosec.pub 3 points 3 months ago The folks at NIST know what they're talking about. The US government directed them to develop security policy for government information systems in 2002 (FISMA) - they've been thinking about how to do this properly for 24 years. If you happen to work for a US government agency of any kind, you can basically tell your boss "NIST guidance says we should do X" and compliance is technically required by law (within the context of security policies that apply to your agency's work area). If you work for a company that does business with the US government, there are similar compliance policies also published by NIST that you should be following (and your company could lose its contracts if it is not compliant). permalink fedilink source parent
[β] Draegur@lemmy.zip 3 points 3 months ago (1 child) Wow it's almost as though somebody in there reads xkcd and knows about correct horse battery staple! permalink fedilink source parent hideshow 2 child comments replies: [β] NaibofTabr@infosec.pub 3 points 3 months ago The folks at NIST know what they're talking about. The US government directed them to develop security policy for government information systems in 2002 (FISMA) - they've been thinking about how to do this properly for 24 years. If you happen to work for a US government agency of any kind, you can basically tell your boss "NIST guidance says we should do X" and compliance is technically required by law (within the context of security policies that apply to your agency's work area). If you work for a company that does business with the US government, there are similar compliance policies also published by NIST that you should be following (and your company could lose its contracts if it is not compliant). permalink fedilink source parent
[β] NaibofTabr@infosec.pub 3 points 3 months ago The folks at NIST know what they're talking about. The US government directed them to develop security policy for government information systems in 2002 (FISMA) - they've been thinking about how to do this properly for 24 years. If you happen to work for a US government agency of any kind, you can basically tell your boss "NIST guidance says we should do X" and compliance is technically required by law (within the context of security policies that apply to your agency's work area). If you work for a company that does business with the US government, there are similar compliance policies also published by NIST that you should be following (and your company could lose its contracts if it is not compliant). permalink fedilink source parent
[β] negativenull@piefed.world [S] 8 points 3 months ago (1 child) Static password with good 2FA is the way to go. permalink fedilink source parent hideshow 2 child comments replies: [β] mrsemi@lemmy.world 7 points 3 months ago* (1 child) I ran into some app a while back that required 2fa "text you a code" to log in every time. If you put in the wrong password, it still sent you the 2fa... Which it would accept for login. I'm honestly not sure if it ever even checked the password. permalink fedilink source parent hideshow 2 child comments replies: [β] negativenull@piefed.world [S] 5 points 3 months ago (1 child) I've seen an increase of sites that bypass passwords altogether and rely on 2fa (claude.ai was one I noticed the otherday) permalink fedilink source parent hideshow 2 child comments replies: [β] dual_sport_dork@lemmy.world 10 points 3 months ago (1 child) That's... not 2FA anymore. It's reverted to 1FA, now with sprinkles on it. permalink fedilink source parent hideshow 2 child comments replies: [β] jaybone@lemmy.zip 3 points 3 months ago Those arenβt sprinkles. permalink fedilink source parent
[β] mrsemi@lemmy.world 7 points 3 months ago* (1 child) I ran into some app a while back that required 2fa "text you a code" to log in every time. If you put in the wrong password, it still sent you the 2fa... Which it would accept for login. I'm honestly not sure if it ever even checked the password. permalink fedilink source parent hideshow 2 child comments replies: [β] negativenull@piefed.world [S] 5 points 3 months ago (1 child) I've seen an increase of sites that bypass passwords altogether and rely on 2fa (claude.ai was one I noticed the otherday) permalink fedilink source parent hideshow 2 child comments replies: [β] dual_sport_dork@lemmy.world 10 points 3 months ago (1 child) That's... not 2FA anymore. It's reverted to 1FA, now with sprinkles on it. permalink fedilink source parent hideshow 2 child comments replies: [β] jaybone@lemmy.zip 3 points 3 months ago Those arenβt sprinkles. permalink fedilink source parent
[β] negativenull@piefed.world [S] 5 points 3 months ago (1 child) I've seen an increase of sites that bypass passwords altogether and rely on 2fa (claude.ai was one I noticed the otherday) permalink fedilink source parent hideshow 2 child comments replies: [β] dual_sport_dork@lemmy.world 10 points 3 months ago (1 child) That's... not 2FA anymore. It's reverted to 1FA, now with sprinkles on it. permalink fedilink source parent hideshow 2 child comments replies: [β] jaybone@lemmy.zip 3 points 3 months ago Those arenβt sprinkles. permalink fedilink source parent
[β] dual_sport_dork@lemmy.world 10 points 3 months ago (1 child) That's... not 2FA anymore. It's reverted to 1FA, now with sprinkles on it. permalink fedilink source parent hideshow 2 child comments replies: [β] jaybone@lemmy.zip 3 points 3 months ago Those arenβt sprinkles. permalink fedilink source parent
[β] jaybone@lemmy.zip 3 points 3 months ago Those arenβt sprinkles. permalink fedilink source parent