this post was submitted on 20 Aug 2024
592 points (98.8% liked)

Cybersecurity - Memes

1951 readers
1 users here now

Only the hottest memes in Cybersecurity

founded 1 year ago
MODERATORS
592
submitted 2 months ago* (last edited 2 months ago) by cron to c/cybersecuritymemes@lemmy.world
 

This practice is not recommended anymore, yet still found in many enterprises.

you are viewing a single comment's thread
view the rest of the comments
[–] DeviantOvary@lemmy.world 3 points 2 months ago (5 children)

We have three month password expiry policy on AD accounts, but the requirements aren't extreme. We'd do away with it, but then we have our own CEO writing their password down on a piece of paper and giving it to us to troubleshoot their laptop (we have admin accounts for a reason ffs), after being repeatedly told not to, forcing employees to rotate their passwords suddenly doesn't sound too crazy. People are just way too irresponsible sometimes. Plus, we need to have it for certifications, so there's that.

[–] MimicJar@lemmy.world 8 points 2 months ago (2 children)

Which certifications? NIST standards don't recommend regular rotations anymore.

[–] DeviantOvary@lemmy.world 1 points 2 months ago

I would need to check (not in charge of it), but I do remember in the fat stack of guidelines we got there was the password policy of 90 days. However, the point still stands that some people have no digital hygiene and will write down and share their passwords in plain text for all to see even if we didn't enforce password expiry. Though in all honesty, there's no winning combination when so many don't truly give a shit about digital security. As long as they can flaunt a certificate.

load more comments (1 replies)
load more comments (3 replies)