Click here to Skip to main content
15,891,253 members

Welcome to the Lounge

   

For discussing anything related to a software developer's life but is not for programming questions. Got a programming question?

The Lounge is rated Safe For Work. If you're about to post something inappropriate for a shared office environment, then don't post it. No ads, no abuse, and no programming questions. Trolling, (political, climate, religious or whatever) will result in your account being removed.

 
GeneralRe: Password policy Pin
Robert/Not The Pirate9-Mar-18 20:14
professionalRobert/Not The Pirate9-Mar-18 20:14 
GeneralRe: Password policy Pin
PIEBALDconsult8-Mar-18 1:40
mvePIEBALDconsult8-Mar-18 1:40 
GeneralRe: Password policy Pin
Eddy Vluggen8-Mar-18 1:50
professionalEddy Vluggen8-Mar-18 1:50 
GeneralRe: Password policy Pin
Nathan Minier8-Mar-18 1:53
professionalNathan Minier8-Mar-18 1:53 
GeneralRe: Password policy Pin
Eddy Vluggen8-Mar-18 2:23
professionalEddy Vluggen8-Mar-18 2:23 
GeneralRe: Password policy Pin
Nathan Minier8-Mar-18 2:35
professionalNathan Minier8-Mar-18 2:35 
GeneralRe: Password policy Pin
Eddy Vluggen8-Mar-18 2:39
professionalEddy Vluggen8-Mar-18 2:39 
GeneralRe: Password policy Pin
Nathan Minier8-Mar-18 2:51
professionalNathan Minier8-Mar-18 2:51 
I disagree. There is no "control the entire chain" when a user can use the same password on my system as on a third party system, and I have no idea what precautions that system might have in place. Compared to the risk of compromise of credentials through third parties, the risk that an employee might keep a written ledger of passwords (or use a password manager) is much easier to accept.

As an SA or ISSO, I have no control over what passwords users have on other systems; but if I make them change it often enough I can reduce the risk of password reuse, and risk reduction is all that you can do in security. Not having password change requirements is frankly "lazy", as you are not only putting your system at risk, but any other that the user might have an account with.
"There are three kinds of lies: lies, damned lies and statistics."
- Benjamin Disraeli

GeneralRe: Password policy Pin
Eddy Vluggen8-Mar-18 2:55
professionalEddy Vluggen8-Mar-18 2:55 
GeneralRe: Password policy Pin
Nathan Minier8-Mar-18 3:11
professionalNathan Minier8-Mar-18 3:11 
GeneralRe: Password policy Pin
Eddy Vluggen8-Mar-18 12:58
professionalEddy Vluggen8-Mar-18 12:58 
GeneralRe: Password policy Pin
Nathan Minier9-Mar-18 1:27
professionalNathan Minier9-Mar-18 1:27 
GeneralRe: Password policy Pin
Eddy Vluggen9-Mar-18 3:15
professionalEddy Vluggen9-Mar-18 3:15 
GeneralRe: Password policy Pin
Nathan Minier9-Mar-18 4:15
professionalNathan Minier9-Mar-18 4:15 
GeneralRe: Password policy Pin
Eddy Vluggen9-Mar-18 5:36
professionalEddy Vluggen9-Mar-18 5:36 
GeneralRe: Password policy Pin
ZurdoDev8-Mar-18 2:09
professionalZurdoDev8-Mar-18 2:09 
GeneralRe: Password policy Pin
raddevus8-Mar-18 2:28
mvaraddevus8-Mar-18 2:28 
GeneralRe: Password policy Pin
A_Griffin8-Mar-18 5:09
A_Griffin8-Mar-18 5:09 
GeneralRe: Password policy Pin
raddevus8-Mar-18 6:45
mvaraddevus8-Mar-18 6:45 
GeneralRe: Password policy Pin
Tim Carmichael8-Mar-18 2:50
Tim Carmichael8-Mar-18 2:50 
GeneralRe: Password policy Pin
A_Griffin8-Mar-18 4:55
A_Griffin8-Mar-18 4:55 
GeneralRe: Password policy Pin
dandy728-Mar-18 3:24
dandy728-Mar-18 3:24 
GeneralRe: Password policy Pin
Scott Serl8-Mar-18 6:04
Scott Serl8-Mar-18 6:04 
GeneralRe: Password policy Pin
dandy728-Mar-18 10:47
dandy728-Mar-18 10:47 
GeneralRe: Password policy Pin
TheGreatAndPowerfulOz8-Mar-18 4:36
TheGreatAndPowerfulOz8-Mar-18 4:36 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.