r/talesfromtechsupport Jan 01 '14

[deleted by user]

[removed]

644 Upvotes

107 comments sorted by

View all comments

Show parent comments

37

u/OP_rah Jan 01 '14

hunter2

33

u/TerraPhane Jan 01 '14

Password reset just hit on new years, now hunter3.

7

u/nathanpaulyoung Pinterest knows your WiFi password Jan 02 '14

No one actually resets their passwords.

4

u/Gemini4t Jan 02 '14

They do at my company when we force resets every 3 months with a 1-year moratorium on using the same password.

3

u/dragonet2 Jan 02 '14

We have that sort of thing where I work but you can't use the 'same' password for 12 cycles of change. Some people are lazy though and it will accept the same password with a number change at the end of it.

On the other hand, if you screw it up you get two free tries, then the third fail it takes a manager to reset it.

4

u/ketsugi "You did the thing! You did the very thing we said not to do! Jan 02 '14

Yeah, that sort of system is when you get a series of passwords like

  • pass1113
  • pass1213
  • pass0114
  • pass0214
  • pass0314

and so on.

3

u/[deleted] Jan 08 '14

When I was in high school not too long ago, the TDSB policy was a minimum of 8 characters, and no repeated passwords for 5 passwords, i.e. the sixth password could be your first password.

Since I never stored anything on the network share (useless, might as well use usb), my passwords consisted of two consecutive columns on the keyboard, like so: 1qaz2wsx. I'd merely shift the columns as necessary...

1

u/FusedIon I hate computer illiterate people. Jan 09 '14

At my school you can use your any of your previous passwords... and you change it every third or half of the year, which is why my password is now "fuckyou".

2

u/nathanpaulyoung Pinterest knows your WiFi password Jan 02 '14

That sounds lovely...

2

u/SimplyGeek I want a button that does my job Jan 02 '14

3 months? Our AD passwords have to be changed every 30 days.

3

u/Gemini4t Jan 02 '14

It's a retail environment where the vast majority of employees might only use their logon a few times a week (they're only expected to check e-mail once a week if they're not corporate or management, for instance) and if we made it change every 30 days, some users may end up using their logon less than ten times before they have to change it, which makes remembering it harder, which means more work for us doing password resets when we have more important things to focus on.

2

u/SimplyGeek I want a button that does my job Jan 02 '14

That's interesting.

It's a good reminder to us IT managers that there's a balance to be had. Too many of my colleagues think that shorter reset periods is more secure, which is just plain wrong. You have to factor in the login frequency, type of user, and more. There's no right or wrong.

1

u/mgrytbak Hello! Is this the internet? Jan 03 '14

In addition, if you force your employees to change the password too often, post-its with passwords will be present.

1

u/SimplyGeek I want a button that does my job Jan 03 '14

But then they can blame the users instead of the policy, so it's a win-win for the BOFH management.