Current Events > we use the most insanely ridiculous password system at work

Topic List
Page List: 1
treewojima
06/01/17 11:16:37 AM
#1:


you log in to the main application using only a password, no username. when creating a password, you enter 5 characters of your choice, then the program generates an additional three characters for you. it resets every month, and you cannot repeat that same sequence of 5 characters at all within a 24 month period. that 8 letter "password" is your sole identifier
... Copied to Clipboard!
Baneposting
06/01/17 11:20:50 AM
#2:


I like the system we use better: "how about you take responsibility for sharing your password since you're using cloud based accounts. And if it's a Windows PC and you leave your door unlocked, you're responsible if people do stupid shit. Same if you leave yourself logged in."

Seems to work.
... Copied to Clipboard!
Questionmarktarius
06/01/17 11:20:50 AM
#3:


This is why work PCs can be "hacked" by simply flipping over the keyboard.
... Copied to Clipboard!
ToonLinkWithGun
06/01/17 11:29:52 AM
#4:


Ours is set up to where each time you change a password you gave to add 1 more character. I'm up to 10 so far...
---
... Copied to Clipboard!
Mernardi
06/01/17 11:30:30 AM
#5:


ToonLinkWithGun posted...
Ours is set up to where each time you change a password you gave to add 1 more character. I'm up to 10 so far...

That sounds like a bad time.
---
Seek Sanctuary, and you shall find it.
... Copied to Clipboard!
treewojima
06/01/17 11:30:54 AM
#6:


Questionmarktarius posted...
This is why work PCs can be "hacked" by simply flipping over the keyboard.


most of the security features of this application are designed to prevent the end user from using unauthorized third party programs and interfaces. they want you to pay out the nose (monthly, of course) for their expansion modules. so they do all sorts of arbitrary things like limit your login to one instance on one computer at any given time, and then relays every keystroke or mouse click back to a central server, which uses rate limiting to determine whether you're a human or a bot. this makes the interface extremely slow, but hey - at least you're not "cheating"
... Copied to Clipboard!
LightHawKnight
06/01/17 11:31:38 AM
#7:


Baneposting posted...
I like the system we use better: "how about you take responsibility for sharing your password since you're using cloud based accounts. And if it's a Windows PC and you leave your door unlocked, you're responsible if people do stupid shit. Same if you leave yourself logged in."

Seems to work.


That is a fast ass way to destroy a company.
---
The Official Odin of the Shin Megami Tensei IV board.
"You know how confusing the whole good-evil concept is for me."
... Copied to Clipboard!
The Admiral
06/01/17 11:32:04 AM
#8:


Forced monthly password changes just result in a lot of passwords like "April2017," "May2017,' etc.
---
- The Admiral
... Copied to Clipboard!
ToonLinkWithGun
06/01/17 11:32:09 AM
#9:


Mernardi posted...
ToonLinkWithGun posted...
Ours is set up to where each time you change a password you gave to add 1 more character. I'm up to 10 so far...

That sounds like a bad time.

Yeah. I asked the our IT guy about it and his response was, "That's the way I want it."

IT...
---
... Copied to Clipboard!
MutantJohn
06/01/17 11:33:38 AM
#10:


Uh, 8 letter password is really weak O_o
---
"Oh, my mother; oh, my friends, ask the angels, will I ever see heaven again?" - Laura Marling
... Copied to Clipboard!
uwnim
06/01/17 11:35:02 AM
#11:


ToonLinkWithGun posted...
Mernardi posted...
ToonLinkWithGun posted...
Ours is set up to where each time you change a password you gave to add 1 more character. I'm up to 10 so far...

That sounds like a bad time.

Yeah. I asked the our IT guy about it and his response was, "That's the way I want it."

IT...

So is there a maximum password length?
---
I want a pet Lavos Spawn.
[Order of the Cetaceans: Phocoena dioptrica]
... Copied to Clipboard!
ToonLinkWithGun
06/01/17 11:35:52 AM
#12:


uwnim posted...
ToonLinkWithGun posted...
Mernardi posted...
ToonLinkWithGun posted...
Ours is set up to where each time you change a password you gave to add 1 more character. I'm up to 10 so far...

That sounds like a bad time.

Yeah. I asked the our IT guy about it and his response was, "That's the way I want it."

IT...

So is there a maximum password length?

I don't know. I held down a key once and it went forever...so...
---
... Copied to Clipboard!
uwnim
06/01/17 11:37:47 AM
#13:


ToonLinkWithGun posted...
uwnim posted...
ToonLinkWithGun posted...
Mernardi posted...
ToonLinkWithGun posted...
Ours is set up to where each time you change a password you gave to add 1 more character. I'm up to 10 so far...

That sounds like a bad time.

Yeah. I asked the our IT guy about it and his response was, "That's the way I want it."

IT...

So is there a maximum password length?

I don't know. I held down a key once and it went forever...so...

Lol, so I guess eventually the passwords get so long the workers have to quit cause they can't ever remember their password.
---
I want a pet Lavos Spawn.
[Order of the Cetaceans: Phocoena dioptrica]
... Copied to Clipboard!
treewojima
06/01/17 11:46:26 AM
#14:


uwnim posted...
Lol, so I guess eventually the passwords get so long the workers have to quit cause they can't ever remember their password.


it's an ingenious solution that gets the higher paid tenured employees to leave so they can be replaced with fresh meat at lower wages
... Copied to Clipboard!
KiwiTerraRizing
06/01/17 11:47:01 AM
#15:


My job we all have an RSA that generates 6 random numbers for each login.
---
Jake Peralta: World's Grossest Pervert
... Copied to Clipboard!
MutantJohn
06/01/17 11:52:45 AM
#16:


Dude... What's with people in IT thinking something super random but super short is secure?
---
"Oh, my mother; oh, my friends, ask the angels, will I ever see heaven again?" - Laura Marling
... Copied to Clipboard!
LightHawKnight
06/01/17 11:54:12 AM
#17:


MutantJohn posted...
Dude... What's with people in IT thinking something super random but super short is secure?


Cause you gotta work with people who are too dumb to memorize a 12 character password, and forcing them to change it monthly is hard enough. And then trying to force them to not write it down just gets the firing and rehiring process in a huge never ending cycle.
---
The Official Odin of the Shin Megami Tensei IV board.
"You know how confusing the whole good-evil concept is for me."
... Copied to Clipboard!
treewojima
06/01/17 11:56:43 AM
#18:


KiwiTerraRizing posted...
My job we all have an RSA that generates 6 random numbers for each login.


our software predates the concept of cybersecurity lol. it's basically an old AS/400 program that had a GUI created over the years. you can still get to the text backend if necessary
... Copied to Clipboard!
DevsBro
06/01/17 11:57:02 AM
#19:


Ours is set up to where each time you change a password you gave to add 1 more character. I'm up to 10 so far...

I've never had this restriction imposed but I used to do it for sake of not memorizing a whole new password every so often.

I just retired a password that was 19 characters long. Naturally, I decided it was time to start over.
---
... Copied to Clipboard!
Questionmarktarius
06/01/17 12:34:03 PM
#20:


treewojima posted...
Questionmarktarius posted...
This is why work PCs can be "hacked" by simply flipping over the keyboard.


most of the security features of this application are designed to prevent the end user from using unauthorized third party programs and interfaces. they want you to pay out the nose (monthly, of course) for their expansion modules. so they do all sorts of arbitrary things like limit your login to one instance on one computer at any given time, and then relays every keystroke or mouse click back to a central server, which uses rate limiting to determine whether you're a human or a bot. this makes the interface extremely slow, but hey - at least you're not "cheating"

It's even easier than that.
Turn the keyboard over. There's a pretty good chance the password is written on a post-it stuck underneath.
... Copied to Clipboard!
treewojima
06/01/17 12:56:31 PM
#21:


Questionmarktarius posted...
It's even easier than that.
Turn the keyboard over. There's a pretty good chance the password is written on a post-it stuck underneath.


my coworker in accounting keeps her sticky note on the monitor. it's "dino7coq" lol
... Copied to Clipboard!
Mikablu
06/01/17 1:00:57 PM
#22:


MutantJohn posted...
Dude... What's with people in IT thinking something super random but super short is secure?

No one in IT thinks that's actually a good way to do it, but like that other user said, other people are usually too dumb/incompetent to use anything better.

Personally, I use a 56-character nonsensical sentence for my passwords.
... Copied to Clipboard!
FF_Redux
06/01/17 1:02:44 PM
#23:


My job I've been working at for 13 years made it so you can never use the same password again, and you need to change it every 3 months.
---
... Copied to Clipboard!
pinky0926
06/01/17 1:04:10 PM
#24:


I'm generally all for more password security but there comes a point where you're just like "come on, nobody gives this much of a shit".

Like when I signed up to some random message board or something and it required a 12 digit password with one capital letter, 2 numbers and a special character. Seriously, no one will ever remember that password.
---
... Copied to Clipboard!
Questionmarktarius
06/01/17 1:06:24 PM
#25:


pinky0926 posted...
Like when I signed up to some random message board or something and it required a 12 digit password with one capital letter, 2 numbers and a special character. Seriously, no one will ever remember that password.

It's also not as "secure" as whoever is mandating it seems to think.
https://xkcd.com/936/
... Copied to Clipboard!
#26
Post #26 was unavailable or deleted.
pinky0926
06/01/17 1:08:30 PM
#27:


Questionmarktarius posted...
pinky0926 posted...
Like when I signed up to some random message board or something and it required a 12 digit password with one capital letter, 2 numbers and a special character. Seriously, no one will ever remember that password.

It's also not as "secure" as whoever is mandating it seems to think.
https://xkcd.com/936/


There's always a relevant xkcd!! I'll be sure to use this next time I have this argument with someone.
---
... Copied to Clipboard!
Mikablu
06/01/17 1:09:19 PM
#28:


pinky0926 posted...
Questionmarktarius posted...
pinky0926 posted...
Like when I signed up to some random message board or something and it required a 12 digit password with one capital letter, 2 numbers and a special character. Seriously, no one will ever remember that password.

It's also not as "secure" as whoever is mandating it seems to think.
https://xkcd.com/936/


There's always a relevant xkcd!! I'll be sure to use this next time I have this argument with someone.

That comic is actually why I have a nonsensical sentence as my password.
... Copied to Clipboard!
MutantJohn
06/01/17 1:20:59 PM
#29:


Mikablu posted...
pinky0926 posted...
Questionmarktarius posted...
pinky0926 posted...
Like when I signed up to some random message board or something and it required a 12 digit password with one capital letter, 2 numbers and a special character. Seriously, no one will ever remember that password.

It's also not as "secure" as whoever is mandating it seems to think.
https://xkcd.com/936/


There's always a relevant xkcd!! I'll be sure to use this next time I have this argument with someone.

That comic is actually why I have a nonsensical sentence as my password.

Yup. Don't use real words otherwise you open yourself up to dictionary attacks where random words from a dictionary are permuted.
---
"Oh, my mother; oh, my friends, ask the angels, will I ever see heaven again?" - Laura Marling
... Copied to Clipboard!
ProfDE
06/01/17 4:01:48 PM
#30:


Be sure to throw in a word like covfefe in your sentence for good measure.
---
... Copied to Clipboard!
Topic List
Page List: 1