logoalt Hacker News

Joel_Mckayyesterday at 5:34 PM2 repliesview on HN

Mostly, it forces dead accounts off the system, as lay off notices are sent the day after.

It is mostly about ensuring some busy admin doesn't have to inventory every user permission.

Rotating domain logins form a similar function of booting inactive users.

2FA actually may make a system weaker, as people can MITM for $23 using a bogus telecom service and password reset. =3


Replies

dragonwriteryesterday at 11:02 PM

> It is mostly about ensuring some busy admin doesn't have to inventory every user permission.

So, its a bad authn practice that is maintained to mitigate the impacts of bad authz practices (you make authn less secure when people are intended to be authorized, in the hopes than when they aren't and you haven't cleaned up their permissions, the password expiration will cause authn failures so the fact that their authorization hasn't been revoked won't matter), instead of adopting good authn and authz practices?

show 1 reply
MengerSpongeyesterday at 7:22 PM

SMS 2FA is harmful. Fortunately, other 2FA modalities are susceptible to that MITM attack