[-] Hasherm0n@lemmy.world 18 points 1 day ago

You are correct.

For anyone else unaware, the schtick of the account was they'd always rate dogs with ratings of x/10 with x always being greater than 10. It was pretty funny how often people would get upset over this.

[-] Hasherm0n@lemmy.world 9 points 4 days ago* (last edited 4 days ago)

What you want is NIST 800-63b https://pages.nist.gov/800-63-3/sp800-63b.html#memsecret

Specifically sections 5.1.1.1 and 5.1.1.2.

Excerpt from 5.1.1.2 pertaining to complexity and rotation requirements:

Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.

Appendix A of the document contains their reasoning for changing from the previous common wisdom.

The tl;dr of their changes boil down to length is more important than any other factor when it comes to password security.

Edit to add:

In my personal opinion, organizations should be trying to move away from passwords as much as possible. If your IT team seems to think this system is so important that they need to rotate passwords every month, they should probably be transitioning to hardware security tokens, passkeys, or worst case, password with non-sms MFA.

Now I know nothing about the actual circumstances and I know there are plenty of reasons why that may not be possible in this specific case, but I'd feel remiss if I didn't mention it.

[-] Hasherm0n@lemmy.world 2 points 4 days ago

This is what I grew up calling it was well.

[-] Hasherm0n@lemmy.world 28 points 4 days ago

Any organization still doing this is a decade behind best practices. NIST published new recommendations years ago that specified getting rid of the practice of regular forced password resets specifically because they encourage bad practices that make passwords weaker.

Of course it doesn't help that there are some industry compliance standards that have refused to update their requirements, but I don't know of any that would require monthly password changes.

[-] Hasherm0n@lemmy.world 5 points 5 days ago

They actually have a fairly comprehensive training program setup through their "University." They also mix in foreign contractors, usually from China.

[-] Hasherm0n@lemmy.world 1 points 6 days ago

My dad cracked three ribs while surfing in his 20s. He caught a wave much larger than normal, fell off his board near the top and landed flat on his back.

[-] Hasherm0n@lemmy.world 58 points 1 month ago

To give you a slightly more serious answer, there's a trope in America of the girl friend's dad doing something to "subtly intimidate" the boy friend by casually cleaning a gun or having one within sight the first time they meet. The implication of course is supposed to be something along the lines of "I've got this and if you try anything funny with my daughter, I'll use it on you"

It's dumb but I've also known more than a few people who have experienced this first hand.

[-] Hasherm0n@lemmy.world 97 points 2 months ago

I'm one of those people. I haven't played in years. I may never have played again. I only found out because my daughter is now at an age where she asked if we could play together. I received no notice from Microsoft and I don't do social media so it was a complete surprise to me when I couldn't log in, then find out through their support that I had lost access to something I had legally paid for.

[-] Hasherm0n@lemmy.world 31 points 2 months ago

It was pointed out to me once that the engine room scenes were filmed in a brewery and now I can't unsee it.

[-] Hasherm0n@lemmy.world 46 points 4 months ago

IIRC that was on the set of one of the Hobbit movies.

The Lord of the Rings was shot mostly using practical effects.

[-] Hasherm0n@lemmy.world 63 points 5 months ago

One of my favorite managers once told me while I was struggling with a severe case of imposter syndrome "if you're faking it well enough that others can't tell, you might not be faking it as much as you think."

[-] Hasherm0n@lemmy.world 31 points 11 months ago

Fuckin do it, be free

167

Tritip, ribs, roasted corn, garlic bread. Didn't get as many pics as I had planned to, too busy cooking 😁.

view more: next ›

Hasherm0n

joined 1 year ago