Earlier quoted context omitted.
Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.
It leads to less security as it is more likely that the new password will just be an old one with an incremented number at the end.
Thanks FedEx, this is why we keep getting phished
151–160 of 576 posts
Re: Thanks FedEx, this is why we keep getting phished
#152Earlier quoted context omitted.
Clearly the safer option is sending the terms via CD https://t3n.de/news/sparkasse-digital-strategie-cds-per-post... Since no-one has a CD drive in their computer anymore, the security risk is negligible
And even if you do have a CD drive in your computer, the risk is still lower than a USB stick. A CD contains only data, it cannot do things like emulating a keyboard. The worst it can do is shatter when your high-speed DVD-ripping drive spins it up a bit too fast.
https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
Re: Thanks FedEx, this is why we keep getting phished
#153A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…
Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…
While I know this may be fruitless, it might be worthwhile to point out to them that the official guidance from NIST and similar organizations is now not to do this.
The IT department where I work required yearly password changes up until I brought this change to their attention, at which point they changed to simply recommending a password change if you have reason to believe it might have been compromised.
Re: Thanks FedEx, this is why we keep getting phished
#154Earlier quoted context omitted.
Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…
Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.
If your company does forced password updates, they are not following the NIST recommendation: https://pages.nist.gov/800-63-FAQ/#q-b05
If your company is not following the NIST recommendation, they are incompetent, and will be held liable in case of a breach.
Re: Thanks FedEx, this is why we keep getting phished
#155https://www.bleepingcomputer.com/news/security/uk-gov-keeps-...
Re: Thanks FedEx, this is why we keep getting phished
#156Not that I’m endorsing the use of smart phones, but FedEx does have a mobile application. Why not just use that for notifications regarding deliveries?
The FedEx one is meh and does afaik, but some (looking at you dhl) are almost useless as they provide little information (tracking info is hidden sometimes), sometimes do not allow you to add the parcel as it has a tracking code from a foreighn service which you cannot use and you have to figure out the local one, are full of "news" also known as ads and do not allow you to select the dropoff location closest to you…
Re: Thanks FedEx, this is why we keep getting phished
#157Re: Thanks FedEx, this is why we keep getting phished
#158Re: Thanks FedEx, this is why we keep getting phished
#159In a Blackhat talk several years ago Adam Shostak had a clever term for companies interacting with you in ways that were indistinguishable from scammers. But I can't remember what the memorable term was.
Anyone found this? Can you remember the episode?
https://i.blackhat.com/us-18/Wed-August-8/us-18-Shostack-Thr...
He used the term "scamicry": legit communications that mimic scams. For example when a company calls you directly and asks for your security details, but offer you no way to verify who they are first.
Re: Thanks FedEx, this is why we keep getting phished
#160Earlier quoted context omitted.
Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…
I forget who puts that stuff out NIST/STIG(?) but IIRC in the recent few years they determined that rotating passwords like that was basically security theater and wasn't worth the damage to the staffs productivity
NIST has very good password complexity and management guidelines. Just USE THEM! It’s not that hard!
How do you have billion dollar companies that can’t RTFM.