Earlier quoted context omitted.
I forget who puts that stuff out NIST/STIG(?) but IIRC in the recent few years they determined that rotating passwords like that was basically security theater and wasn't worth the damage to the staffs productivity
NIST, whose guidelines, somehow, even other federal departments and agencies usually don’t follow. NIST has very good password complexity and management guidelines. Just USE THEM! It’s not that hard! How do you have billion dollar companies that can’t RTFM.
Thanks FedEx, this is why we keep getting phished
181–190 of 576 posts
Re: Thanks FedEx, this is why we keep getting phished
#182Earlier quoted context omitted.
Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.
In combination with forced changes, it leads to… Password1 Password2 Password3 Etc
Re: Thanks FedEx, this is why we keep getting phished
#183A few months ago I got an email from the IT center of the company I work for that was dodgier than any phishing email I have ever received: - Coming from a domain that looks nothing like the official domain of the company, rather some generic @itservice.com or something. - Subject: "URGENT: your account is expiring soon". - Multiple links provided in the email body, all illegible and multiple lines long, none of them…
Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.
Re: Thanks FedEx, this is why we keep getting phished
#184Re: Thanks FedEx, this is why we keep getting phished
#185Earlier quoted context omitted.
Healthcare companies in the US send the most scammy looking links for payment processing you’ve ever seen - things like my-healthcare-billing.net It’s insane.
Yeah I got a text from one of these a couple years ago. Something like. “You have an overdue doctor bill of $183.56, please kindly pay immediately at this link: http://my-doctorpay.net/defintelylegit123 . Thx!” Didn’t even include the name of the doctor or office, but after calling the only doctors office I had used recently it was apparently legit. I let them know whatever company handles their billing is completely…
This is something that only people like us can see. The rest of the world doesn’t care about the problem, and even if they did, they have zero incentive to fix it.
Re: Thanks FedEx, this is why we keep getting phished
#186Earlier quoted context omitted.
Is blocking the last 20 passwords a bad thing? I agree the other stuff is bad, but to me, that part doesn't seem bad.
In combination with forced changes, it leads to… Password1 Password2 Password3 Etc
PasswordFebruary2024!
Where month and year update on the date of forced password change.
Re: Thanks FedEx, this is why we keep getting phished
#187Earlier quoted context omitted.
Our IT did the exact same thing with expiring m365 passwords. They weren’t using the corp domain, typos all over and the URL was obscured using a bizarre link shortener. The same guys also force us to change our passwords every 6 months and block the last twenty. Passwords we have to enter in systems that can’t pull directly from password managers and thus have to type 10-20 per day. Guess the average strength of an…
The lack of use of a non-corp domain, the typos and the use of shortened links does sound like a form of incompetence, probably at the management layer. However, the password rotation requirement was until relatively recently something that many IT auditors would actually recommend , even though it leads directly to bad user password choices. In fact I wouldn't be at surprised to learn that was still the case in a lo…
Re: Thanks FedEx, this is why we keep getting phished
#188Earlier quoted context omitted.
The lack of use of a non-corp domain, the typos and the use of shortened links does sound like a form of incompetence, probably at the management layer. However, the password rotation requirement was until relatively recently something that many IT auditors would actually recommend , even though it leads directly to bad user password choices. In fact I wouldn't be at surprised to learn that was still the case in a lo…
Fortunately NIST has specific advice that recommends against that which is admissible in court (in the US). I'm not sure how to work through the bureaucracy to do this, but your company should sue them in court for incompetence to get their money back.
Re: Thanks FedEx, this is why we keep getting phished
#189Re: Thanks FedEx, this is why we keep getting phished
#190I found a Reddit post today about a German bank mailing USB sticks containing their new general terms and conditions: https://www.reddit.com/r/de/comments/1ax7ky3/milde_interessa... You can't make this up.