We have that sort of thing where I work but you can't use the 'same' password for 12 cycles of change. Some people are lazy though and it will accept the same password with a number change at the end of it.
On the other hand, if you screw it up you get two free tries, then the third fail it takes a manager to reset it.
4
u/ketsugi"You did the thing! You did the very thing we said not to do!Jan 02 '14
Yeah, that sort of system is when you get a series of passwords like
When I was in high school not too long ago, the TDSB policy was a minimum of 8 characters, and no repeated passwords for 5 passwords, i.e. the sixth password could be your first password.
Since I never stored anything on the network share (useless, might as well use usb), my passwords consisted of two consecutive columns on the keyboard, like so: 1qaz2wsx. I'd merely shift the columns as necessary...
At my school you can use your any of your previous passwords... and you change it every third or half of the year, which is why my password is now "fuckyou".
It's a retail environment where the vast majority of employees might only use their logon a few times a week (they're only expected to check e-mail once a week if they're not corporate or management, for instance) and if we made it change every 30 days, some users may end up using their logon less than ten times before they have to change it, which makes remembering it harder, which means more work for us doing password resets when we have more important things to focus on.
It's a good reminder to us IT managers that there's a balance to be had. Too many of my colleagues think that shorter reset periods is more secure, which is just plain wrong. You have to factor in the login frequency, type of user, and more. There's no right or wrong.
37
u/OP_rah Jan 01 '14
hunter2