I'm Going To Take A Hostage
-
My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D
I too particularly despise this policy! :O :( :mad::~ That sure must have been a [true password story](https://letvent.com/2014/05/09/creating-a-password-boiled-cabbage/), somehow!
A new .NET Serializer All in one Menu-Ribbon Bar Taking over the world since 1371!
-
My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D
-
My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D
MadGerbil wrote:
If you write a password management system and force people to change passwords every 30 days
this is because if your password is compromised and I have it, then I have only 30 days to use it, before I can't anymore. Not so great for you and the company during those 30 days, but it is better than nothing, I guess. It is a valid level of security. You should be more than glad they don't make you change your password every week. And no, they are not bad people for doing this. No more as bad as the doctor who tells you to quit smoking. I agree it is frustrating, very much so.
-
Quote:
If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE.
:thumbsup: I completely agree!
-
My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D
MadGerbil wrote:
Because of this I need to take a hostage.
If you have foul play in mind, I have a list! :)
I'm not sure how many cookies it makes to be happy, but so far it's not 27. JaxCoder.com
-
MadGerbil wrote:
If you write a password management system and force people to change passwords every 30 days
this is because if your password is compromised and I have it, then I have only 30 days to use it, before I can't anymore. Not so great for you and the company during those 30 days, but it is better than nothing, I guess. It is a valid level of security. You should be more than glad they don't make you change your password every week. And no, they are not bad people for doing this. No more as bad as the doctor who tells you to quit smoking. I agree it is frustrating, very much so.
The only way my password can be compromised is by mind-reading... Or I give it away... So the site (that obviously does not store it :laugh:) has no reason to be so hard on me...
"The only place where Success comes before Work is in the dictionary." Vidal Sassoon, 1928 - 2012
-
My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D
MadGerbil wrote:
If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement.
it's not a secure password because you will not be able to remember it and you will write it down on a post-it or copy it on a regular text file on your desktop; or you click on the "I forgot my password" button. Anyway, agreed. I hate when I have to change passwords.
I'd rather be phishing!
-
MadGerbil wrote:
Because of this I need to take a hostage.
If you have foul play in mind, I have a list! :)
I'm not sure how many cookies it makes to be happy, but so far it's not 27. JaxCoder.com
Mike Hankey wrote:
I have a list!
By any chance, is Mike short for Mikado [^] ?
"The difference between genius and stupidity is that genius has its limits." - Albert Einstein
"If you are searching for perfection in others, then you seek disappointment. If you seek perfection in yourself, then you will find failure." - Balboos HaGadol Mar 2010
-
MadGerbil wrote:
If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement.
it's not a secure password because you will not be able to remember it and you will write it down on a post-it or copy it on a regular text file on your desktop; or you click on the "I forgot my password" button. Anyway, agreed. I hate when I have to change passwords.
I'd rather be phishing!
-
MadGerbil wrote:
If you write a password management system and force people to change passwords every 30 days
this is because if your password is compromised and I have it, then I have only 30 days to use it, before I can't anymore. Not so great for you and the company during those 30 days, but it is better than nothing, I guess. It is a valid level of security. You should be more than glad they don't make you change your password every week. And no, they are not bad people for doing this. No more as bad as the doctor who tells you to quit smoking. I agree it is frustrating, very much so.
Slacker007 wrote:
this is because if your password is compromised and I have it, then I have only 30 days to use it, before I can't anymore. Not so great for you and the company during those 30 days, but it is better than nothing, I guess.
What the experts say: Time for Password Expiration to Die | SANS Security Awareness[^]
-
MadGerbil wrote:
If you write a password management system and force people to change passwords every 30 days
this is because if your password is compromised and I have it, then I have only 30 days to use it, before I can't anymore. Not so great for you and the company during those 30 days, but it is better than nothing, I guess. It is a valid level of security. You should be more than glad they don't make you change your password every week. And no, they are not bad people for doing this. No more as bad as the doctor who tells you to quit smoking. I agree it is frustrating, very much so.
The problem with systems that force people to regularly change passwords is that people have a habit of simply incrementing a number at the end of a password. So the chances are that if I know your password, I can just try incrementing the number at the end until I get your current password which has probably just been incremented by one.
“That which can be asserted without evidence, can be dismissed without evidence.”
― Christopher Hitchens
-
My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D
This means they are storing all your previous passwords. Do they guarantee you that their password storage is never going to be compormised?
-
This means they are storing all your previous passwords. Do they guarantee you that their password storage is never going to be compormised?
-
This means they are storing all your previous passwords. Do they guarantee you that their password storage is never going to be compormised?
Hopefully a salted hash of your previous passwords. But given some of the code that keeps cropping up in QA, I wouldn't guarantee it.
"These people looked deep within my soul and assigned me a number based on the order in which I joined." - Homer
-
This means they are storing all your previous passwords. Do they guarantee you that their password storage is never going to be compormised?
You have no need to store the old passwords... a one-way hash will do... But if you store one-way hash what do you afraid of?
"The only place where Success comes before Work is in the dictionary." Vidal Sassoon, 1928 - 2012
-
You have no need to store the old passwords... a one-way hash will do... But if you store one-way hash what do you afraid of?
"The only place where Success comes before Work is in the dictionary." Vidal Sassoon, 1928 - 2012
Kornfeld Eliyahu Peter wrote:
what do you afraid of?
As Richard says: Go to QA and see what some idiots developers are doing in the real world ... :sigh:
"I have no idea what I did, but I'm taking full credit for it." - ThisOldTony AntiTwitter: @DalekDave is now a follower!
-
Kornfeld Eliyahu Peter wrote:
what do you afraid of?
As Richard says: Go to QA and see what some idiots developers are doing in the real world ... :sigh:
"I have no idea what I did, but I'm taking full credit for it." - ThisOldTony AntiTwitter: @DalekDave is now a follower!
But of course... only speaking in theory... (that's the reason that I try to avoid opening accounts on any site, and using google's login if I can)
"The only place where Success comes before Work is in the dictionary." Vidal Sassoon, 1928 - 2012
-
Hopefully a salted hash of your previous passwords. But given some of the code that keeps cropping up in QA, I wouldn't guarantee it.
"These people looked deep within my soul and assigned me a number based on the order in which I joined." - Homer
Thanks. New learning today.
-
My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D
-
My credit union forced me to change my password but won't let me use a previous password. I don't know why I get irrationally angry over this - I guess I feel passwords are kind of personal and telling me that I cannot use an old one doesn't improve security at all and seems invasive. If I write insecure passwords changing guest1 to guest2 isn't an improvement. If I write secure passwords changing TsfI$)#%(fikea;f to IDJOfe30235 isn't an improvement. There is more B.S. superstition around password management than I can handle. One of the most boogered things in all of IT are password management systems. If you write a password management system and force people to change passwords every 30 days YOU ARE A BAD PERSON IN REAL LIFE. Because of this I need to take a hostage. I hope she's cute. :D
I may climb a tower over multiple systems, the VPN, Active Directory, Global network, etc. All of them have different expiration policies so syncing up passwords is a real PITA. Don't give me the crap about they all should have different passwords, all those systems are part of the work ecosystem. Currently, I have 3 different passwords because of the timing. There's one of them that expires the fastest, that I can't figure out which part of the environment it controls since I rarely type it.