These are the same companies that don’t support second factors, only have their app as a second factor, or only SMS second factor. Is it too much to ask for smart card or token (yubikey) support?

  • @l_b_iOP
    link
    fedilink
    English
    07 months ago

    I don’t think you’re following.
    First, you are an account holder in my answer not an employee.
    Second, the reason its an issue has nothing to do with the actual password or password security. Frequent changes lead to simpler passwords. Someone is likely just to increment a number, so a new password is barley a hindrance if the previous one is compromised. Frequent changes are going to lead to more password resets, service personnel who have to deal with people forgetting passwords due to frequent resets/ changes are more likely to be complacent allowing an attacker to gain access through a reset. For company based passwords, frequent changes and high complexity requirements are more likely to lead to someone writing a password down near where that password is used.

    • @[email protected]
      link
      fedilink
      English
      07 months ago

      No, you’re not following. (I assumed I was an account holder in that example, but it’s not important.)

      Someone is likely just to increment a number, so a new password is barley a hindrance if the previous one is compromised.

      Not if they use a password manager and click a button to completely randomize a new password. They do not have to worry they forget it, because they only have to memorize their master password.

      KeePass Password Generation Options

      Why would someone who was told to hit that button by IT increment a number instead?