Password policy is mostly bullshit anyway since most “hackers” these days are just performing social engineering on morons with no sense in order to get in.
Ah, now I get it. That’s why they enforce password policies that make the password impossible to remember – you can’t give a hacker your password if you don’t know your password! Genius!
ZeDoTelhado@lemmy.world 3 days ago
There is actually a lot more to this: a lot of people in the it sec crowd have been saying for many years that this habit of the gibberish passwords with symbols capitals and whatnot is actually a net deficit in security. Mostly because for the longest time people had to mostly remember all passwords and the policies for rotation were to aggressive (which lead to “lazy” changes). Nowadays unfortunately we still have people that inherited this thinking and still enforce this, but you also see a lot of people understanding that pass phrases are a lot better (of course should not be a predictable phrase like good morning, but it is possible to make it much better with way less effort)
agamemnonymous@sh.itjust.works 2 days ago
Correct horse battery staple
Hasherm0n@lemmy.world 2 days ago
More that just “… a lot of people…” NIST themselves published real research backing this up over a decade ago.