Earlier quoted context omitted.
And it's even worse if you are accessing Apple services on a non-Apple device. No matter how many times I click "trust device" when logging in to icloud.com it will still make me do the password + one-time code song and dance the next day. Another pointless annoyance - if Face ID fails when making a payment or installing an app (like it frequently does for reasons like sleeping in bed or wearing sunglasses) it won't…
> if Face ID fails when making a payment or installing an app (like it frequently does for reasons like sleeping in bed or wearing sunglasses) it won't fall back to PIN but ask you to enter your Apple account password. What? FaceID will prompt for a re-try. Always. It will never fail once and then refuse to do FaceID. If you can't figure out to lift the sunglasses off your face or sit up in bed for a second, that's n…
Frequent reauth doesn't make you more secure
251–260 of 539 posts
Re: Frequent reauth doesn't make you more secure
#252Re: Frequent reauth doesn't make you more secure
#253Earlier quoted context omitted.
Last time I brought this to our cyber folks, they pointed out that PCI standards require password rotation. So it depends upon which auditors you care about more.
This requirement is in section 8.3.9 of the PCI DSS[0], and only applies to single-factor authentication implementations, two-factor auth removes this requirement. [0] https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard...
[0] https://www.finra.org/filing-reporting/entitlement/password-...
Re: Frequent reauth doesn't make you more secure
#254These are a video games, not a bank account! Please just let me have fun!
Re: Frequent reauth doesn't make you more secure
#255Earlier quoted context omitted.
1234abcd@ it is then for all my accounts.
Password rotation does nothing more than get you to use 1234abcd@ 1234abcd@1 1234abcd@2 1234abcd@3 I'm becoming pretty convinced that at least in the corporate space, we'd be way better off with a required 30 character minimum password, with the only rules being against gross repetition or sequences. (no a * 30 or abcd...yz1234567890 ). Teach people to use passphrases and work on absolutely minimizing the number of t…
1234567890a1234567890@1234567890
Better?No, just longer to type. You can't fix stupid people by making the life of non-stupid people worse.
All you do is for non-stupid people to stop caring and do the easiest thing possible too.
Re: Frequent reauth doesn't make you more secure
#256Earlier quoted context omitted.
Password rotation does nothing more than get you to use 1234abcd@ 1234abcd@1 1234abcd@2 1234abcd@3 I'm becoming pretty convinced that at least in the corporate space, we'd be way better off with a required 30 character minimum password, with the only rules being against gross repetition or sequences. (no a * 30 or abcd...yz1234567890 ). Teach people to use passphrases and work on absolutely minimizing the number of t…
"Your password is too similar to your previous password" Hmm, how would you know that.
Re: Frequent reauth doesn't make you more secure
#257Forced password rotation and expiry seems the bigger problem; given that it causes people to get locked out so often, (e.g. if pw expires when on holiday), — often then requiring travelling to IT, or at least a few hours trying to get IT on the phone to reset, or chasing up colleagues who aren't locked out to get in touch with IT. Many (most?) companies still do it, despite it now not being recommended by NIST: > Ver…
thankfully my current company let me keep my password for the last 3 years
Re: Frequent reauth doesn't make you more secure
#258Earlier quoted context omitted.
And it's even worse if you are accessing Apple services on a non-Apple device. No matter how many times I click "trust device" when logging in to icloud.com it will still make me do the password + one-time code song and dance the next day. Another pointless annoyance - if Face ID fails when making a payment or installing an app (like it frequently does for reasons like sleeping in bed or wearing sunglasses) it won't…
Why in the world does it need you to type a code id you have already accepted it at the other device? This whole flow is stupid, I guess they want to cover their asses.
By requesting a short-lived code, attackers now need to communicate with you at the same time of the attack and somehow convince you to give them that code. Much harder.
Re: Frequent reauth doesn't make you more secure
#259Microsoft has ruined their PC games with this. I hesitate to fire up Minecraft or Master Chief Collection these days because I just _know_ it is going to make me reauth for no apparent reason. I took 2FA off my Microsoft account because of this, so congrats. These are a video games, not a bank account! Please just let me have fun!