• The_v@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    10 hours ago

    The largest issue I have is the randomness of all the different security setups. One requires MFA by e-mail, one requires an authenticator, most require sms, some push to require using their app, and this random page requires a code by phone call. Now they are pushing passkeys and that is a complete cluster.

    What’s ironic is that most of the webpages that push these things don’t reach the “Do I give a fuck?” threshold. The security is usually there to protect against unauthorized use of user stored credit cards. Since I am not liable for any fraudulent charges to the credit card, I really don’t give a fuck about securing the account. Yeah I am reusing passwords, keeping them in plain text in a word doc etc…

    When I worked for other companies, I moderately gave fuck about there security. Not enough to inconvenience me. If they made me change the password constantly, they got the number changing series at the end of the password - $tupidPass#01 Seriously that was my actual work password for over a decade.

    Now my bank account and financial logins. You’d better believe those have every security feature they offer setup. I do not fuck around with those. I give a fuck about those.

    • SaraTonin@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      9 hours ago

      I remember reading an article once which referred to research which suggested that making people change passwords every month made their accounts less secure, because they have to go extra steps to remember them - which usually translates to making them really obvious and/or storing them where they’re easily accessed. In one of my previous jobs where we had to change passwords every month, basically everybody would have their password written on a post-it on their computer monitor.

      • chillpanzee@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        or storing them where they’re easily accessed

        Sticky note under the keyboard is probably still the number one spot.

      • vortexsurfer@lemmy.world
        link
        fedilink
        English
        arrow-up
        3
        ·
        3 hours ago

        Yeah, that’s actually also why it’s no longer considered best practice to force regular password changes. But many places / websites /apps still do, obviously.

      • The_v@lemmy.world
        link
        fedilink
        English
        arrow-up
        6
        ·
        9 hours ago

        In my first job I had like 7 different passwords to access different systems. Each one had different schedule of password reset. They each ended up being on a different reset schedule. I had to reset a password once or twice a week.

        Yeah, everyone had their passwords on a sticky note on their monitor. I once got praise for being the one person without it. I of course had an abreviation for the system with what number series the password was on posted on my monitor.

        • MirthfulAlembic@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          6 hours ago

          This is my current job. I’ve got monthly, every three months, every quarter, once per year… Thank goodness the last service they added has SSO.

        • its_kim_love@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          2
          ·
          8 hours ago

          I had a passkey card where each letter was given a random sequence of uppercase, lowercase, a number and a symbol. With just a four letter word as they key you had a 16 digit random password that was hard to guess even if you had the key sheet.

      • its_kim_love@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        3
        ·
        8 hours ago

        I worked in top secret military stuff and the worst I had was every 4 months on some systems. Monthly seems extremely ineffective.