• pivot_root@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    3 days ago

    Is it? Or is it just a way to record which employees need mandatory cybersecurity “training” that tells them to use a 28 character password with at least one number, one upper case letter, one special character, no strings of 3 or more repeated characters, no strings of 3 or more incremental letters or numbers, and no strings of more than 5 of the same character class?

    • shneancy@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      3 days ago

      if i heard such requirements i’d immediately write my password down on paper, and then just leave it on my desk slightly out of sight of the IT team. and i bet most of my coworkers would do the same

      which tbf, wouldn’t even be that dangerous. i don’t know if this is still true but i was taught that if a hacker has physical access to my machine - a password is going to do fuck all