A few years back, not too long ago, I started working on a new contract assignment at a medium size aerospace manufacturer. I show up and check in with IT department. The system administrator shows me to my desk, and hands me a post it note with my password. Well pass phrase is more like it. It was something like “sliding down the tall building”. I was quite impressed that they encouraged the use of long pass phrases…
I hate password rules
391–400 of 447 posts
Re: I hate password rules
#392Earlier quoted context omitted.
Have you heard about https://haveibeenpwned.com/Passwords ?
Sorry I reread and you said hibp so you know! Why not use the entire set?
Re: I hate password rules
#393A few years back, not too long ago, I started working on a new contract assignment at a medium size aerospace manufacturer. I show up and check in with IT department. The system administrator shows me to my desk, and hands me a post it note with my password. Well pass phrase is more like it. It was something like “sliding down the tall building”. I was quite impressed that they encouraged the use of long pass phrases…
But if we are honest an admin can already access relevant data anyway and you do indeed need to use a user context to access certain settings of some applications. This is especially true for less digitally affine users.
There are workarounds (Windows->Run as...), but that is sometimes insufficient.
About an admin using your user account to start the nukes? That is mostly possible anyway in the usual corporate Windows configuration. He could just change your AD password and log in as you. I would recommend that approach anyway and then force the user to set a new password and informing him why you sabotaged his workstation would also be nice. Far more secure than having the holy grail Excel file.
Re: I hate password rules
#394Earlier quoted context omitted.
This level of negligence should be criminal.
The software industry is full of should-be-criminal forms of negligence. Things are already horrendously bad. Basically every American's identity could stolen at this point. If any nation state or other actor decided to operationalize any of the big leaks -- eg OPM or EquiFax -- the ramifications would be catastrophic. Imagine millions of people losing their retirement accounts and all their savings. Even if you coul…
Re: I hate password rules
#395Earlier quoted context omitted.
> 4. Reset no more than once a year. That would make a lot of people's life terrible. I reset my passwords very frequently (almost every time I log out of a website)
That seems..excessive. What is your motivation for that?
Re: I hate password rules
#396Re: I hate password rules
#397Earlier quoted context omitted.
With secure inter-vm copy-pasting: https://www.qubes-os.org/doc/how-to-copy-and-paste-text/
Impressive level of paranoia. That said, I'd declare it your 'password manager'.
Re: I hate password rules
#398A few years back, not too long ago, I started working on a new contract assignment at a medium size aerospace manufacturer. I show up and check in with IT department. The system administrator shows me to my desk, and hands me a post it note with my password. Well pass phrase is more like it. It was something like “sliding down the tall building”. I was quite impressed that they encouraged the use of long pass phrases…
Pro tip: When you're seeing something really unethical that could eventually rebound on you - write it down. Write down contemporaneously what happened and sign and date it. Much more reliable evidence.
Emailing it to someone seems to be the go-to recommendation online, but you might not want to expose the information at the time. Some alternatives, in descending order of jank: a Google Doc, unlisted Pastebin, either of those but only post the hash and keep the file offline, a proper TSP timestamp - the latter is actually near-trivial these days with something like freeTSA.org.
Re: I hate password rules
#399I hate seeing websites that have odd restrictions like "you can use !, ?, #, and @, but not % or ^". I can't think of a reasonable reason.
Re: I hate password rules
#400Earlier quoted context omitted.
For websites, you're just making your own life harder for no real gain. Even with purely alphanumeric 10 chars, it's not like anyone can exhaust the 36^10 password space over a network with no one noticing. Yet whenever you run into issues with the website or the password manager (or some other non-routine thing... like you're on your phone and need to enter this on a different computer) and have to enter it manually…
I guess you assume that everyone protects their stored hashes.