Readit News logoReadit News
whatsmyusername commented on Microsoft says mandatory password changing is “ancient and obsolete” (2019)   arstechnica.com/informati... · Posted by u/Tomte
quesera · 5 years ago
That's correct. PCI DSS section 8.2.4(a) requires that passwords are changed at least every 90 days.

Other requirements from the same section: retain old passwords to disallow dupes for at least 5 cycles, passwords must be minimum 7 chars, and contain both alpha and numeric.

You might be able to justify non-compliance with a compensating control, but I've never heard of anyone who tried it.

Note that this only applies to employees who are in PCI scope. Most internal staff are not, and should not be!

Similar policies are common for all users though. They pre-date PCI (which is how they became part of PCI DSS) and now PCI's retention of these policies justifies continued use elsewhere. The tail wags the dog.

whatsmyusername · 5 years ago
This is why when I built our systems, I did most of them using a combination of public/private keys and TOTP 2fa. Also severely isolating those systems so that the list of people who need access is as small as possible.

It's orders of magnitude less of a pain in the ass than password cycling.

whatsmyusername commented on Microsoft says mandatory password changing is “ancient and obsolete” (2019)   arstechnica.com/informati... · Posted by u/Tomte
whatsmyusername · 5 years ago
It's not just Microsoft, I believe NIST has the same guidelines now.

Forcing people to constantly change passwords just means they either iterate a number or write them down. It also means they start to resent the tech and people who make them do it. It helps no one.

whatsmyusername commented on The Economics of 24/7 Lo-Fi Hip-Hop YouTube Livestreams   hotpodnews.com/the-econom... · Posted by u/feb
whatsmyusername · 5 years ago
Lofi is huge because it’s not in the RIAA. So you can actually do stuff with it (like stream) and not get sued.
whatsmyusername commented on Show HN: Lofi.cafe   lofi.cafe... · Posted by u/linuz90
whatsmyusername · 5 years ago
That’s real slick. Royalty free Lofi is 90% of my music consumption anymore since the RIAA decided they don’t want their artists to be relevant to anyone who is big on streaming.

Dead Comment

Dead Comment

Dead Comment

Dead Comment

Dead Comment

Dead Comment

u/whatsmyusername

KarmaCake day-2December 20, 2019View Original