”Finally, the company should have enforced a strong password policy that would have prevented our heroes from finding dozens of accounts with “winter2023!” as the password.”
Capitalize that “w”, and you’ve got a password that will pass most PWD policies. Why do they think it was “winter2023!” to begin with? In 90 days when the PWD expires, well, it will be spring of the next year, so…
The better idea is to require passwords with some real entropy, and get rid of expiring passwords. It’s not 1999 anymore.
1. Open a web browser and do a search
2. Read until you find a sentence that you like.
3. Use it as your password
I swear if the ghouls running things had abit more decency and allowed people to actually access and controll their passkeys then that would be the future, everyone would adopt it. The experience is so nice with key pair exchange for ssh. Its just that there i have thr security of knowing exactly where my secret is and how i can manage it, its just a file and i can move it like a file
Nobody wants the risk of getting locked out because of apple and googles walled garden bullshit
Letting users pick their own passwords has always been a mistake. If passwords are needed, the system should choose them.
Expiring passwords are one of my biggest gripes, and I still see them everywhere