Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> always fun rotation of passwords on over 1000 servers in 3 months that were mostly manual because the vendors all charge for an SOW to do that (oh yeah this is a YEARLY activity).

Why do I smell Windows Server 2008?



NIST stopped recommending regular password rotation years ago. Why are mega corps still insisting on this? Security theater? Unknowledgable?


“We’ve always done it this way so we’re not about to change”, or a customer somewhere has an audit checklist that mandates password rotations every 3 months.

I know of people stuck with such a moronic password change policy, and the new password can’t be the same as the last five or whatever. So they change the password five times in a row so they can keep using the same password over and over.

This kind of thing makes me so so so depressed about work. It’s overwhelmingly self inflicted suffering for no benefit, and it makes millions of people miserable for nothing.


MS has their guidance also not recommending password cycling: https://www.microsoft.com/en-us/research/wp-content/uploads/...

But he mentioned servers not users. If those are Windows Servers in AD env, LAPS exists: https://www.microsoft.com/en-us/download/details.aspx?id=468...


Yes and trying to find a bargain on staff.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: