Frequent Password Changes Is a Bad Security Idea
11–20 of 59 posts
Re: Frequent Password Changes Is a Bad Security Idea
#12It's a double sword. The true issue with frequent password change is people really don't want to be creative. They ended up either changing one letter, or adding an extra letter. At least do a quick distance check and deny password at 90% similarity.
Re: Frequent Password Changes Is a Bad Security Idea
#13I usually just make up a crazy long sentence I'll remember, with no logical order in it. Something funny to me so I'll easily remember it. Throw in some assortment of numbers and symbols. Bam! Works like a charm!
Re: Frequent Password Changes Is a Bad Security Idea
#14Re: Frequent Password Changes Is a Bad Security Idea
#15For those who work at corporations with password rotation policies, it may actually be a good way to get creative. This guy changed password rotations into a lifehack: https://medium.com/the-lighthouse/how-a-password-changed-my-... Previous discussion on it: https://news.ycombinator.com/item?id=8015470
Re: Frequent Password Changes Is a Bad Security Idea
#16At a client's who requires frequent password changes, people simply write out their passwords on post it notes that they stick onto their screens. Some security. (That's a bank, by the way).
Re: Frequent Password Changes Is a Bad Security Idea
#17Re: Frequent Password Changes Is a Bad Security Idea
#18Re: Frequent Password Changes Is a Bad Security Idea
#19At a client's who requires frequent password changes, people simply write out their passwords on post it notes that they stick onto their screens. Some security. (That's a bank, by the way).
https://www.schneier.com/blog/archives/2005/06/write_down_yo...
Re: Frequent Password Changes Is a Bad Security Idea
#20Because to me requiring frequent password change seems like the ultimate non-technical management blunder: management wants to say they did something to prevent hacks, so they ask IT to require password changes; IT doesn't want to be blamed so they implement it; users comply with the requirements but can't remember their new password (and don't really care about the company's security in the first place), so they come up with something insecure and keep it somewhere even less secure.