this post was submitted on 29 Apr 2025
102 points (95.5% liked)

iiiiiiitttttttttttt

474 readers
1643 users here now

you know the computer thing is it plugged in?

A community for memes and posts about tech and IT related rage.

founded 1 week ago
MODERATORS
 

TranscriptA meme saying "Society if end users remembered their passwords." it is accompanied by a picture of a futuristic city.

you are viewing a single comment's thread
view the rest of the comments
[–] tophneal@sh.itjust.works 22 points 3 days ago (2 children)

Don’t believe anyone who says constant changing of passwords is “best practice,” it’s not. The constant changing typically leads to less secure passwords and practices by end users.

[–] Ptsf@lemmy.world 2 points 1 day ago* (last edited 1 day ago)

Constant password expiration was/is an attempt to get users to rotate passwords after they themselves have disclosed/otherwise compromised their sign on information or abandoned/orphaned their account. It's a drag net. A stupid one. But ironically if it was enforced on all active accounts, it's a drag net that would've even saved Microsoft from compromise by the Russians. So it does have it's uses in some regard, but to be honest it seems like the state of all security and authentication mechanisms is currently in between 💩 and 🗑️🔥 as far as design and intuition goes. Why I need a password manager for 1000+ accounts instead of being able to generate/sign my own cryptographic authentication tickets in an intuitive way is beyond me. Passkeys is getting there, but having used them, I can still definitively say the implementation is unintuitive trash. (https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/ )

[–] entwine413@lemm.ee 5 points 3 days ago

It's discouraged by NIST now too. Basically the only requirement is that you have some sort of policy in place.