Whats rustling your jimmies?

Hoss

Make America's Team Great Again
<Gold Donor>
31,774
26,458
Exactly.

At least half of the time when I'm prompted enter some motherfucking password with special rules, followed by some assbackwards mark of the beast 2FA - its a case where I literally don't give a fuck about security. Like I would be 100% OK with just remove the password and let me log in with just user name.

Some asshole invented new digital security tricks and every fucking faggot on the planet decided they needed to use it on their thing.

Its like if every door on the planet suddenly had an iris scanner and an armed guard standing next to it. Even though this particular door is just the entrance to a random wooden shack.
I think it's the IT people being self important dipsticks. They like to pretend they are defending NSA secrets. It's just a matter of them ticking some boxes on the server config screen. That's why they didn't even bother to put the password requirements on the webpage. To use your anal ogy, the lock you use on your closet door should be up to you, not mandated by someone who's never seen a closet.
 

Koushirou

Log Wizard
<Gold Donor>
6,094
16,628
One of my biggest password rustles was for the bank I had my car loan with. Once I started using a password manager, I’d throw longer passwords at everything. So when my password rotation came up for the site, I’d throw a 64 char password at it, with all the other requirements it listed, min length, special characters, numbers, etc. But it didn’t list a max length. It took the password with no errors and then I’d go to log in and it’d tell me my password was wrong. Reset again, same thing. Did this a few more times and finally said fuck it and put a min-length password in and hey, it worked. Eventually figured out that there was a 16 character limit on it, but no validation for that on the front-end, nor did it list it in the requirements, and if you gave it something longer, it would take it but just silently cut off the extra on the back-end. Amazing work.
 
  • 1Solidarity
Reactions: 1 user

Haus

I am Big Balls!
<Aristocrat╭ರ_•́>
21,865
90,916
I think it's the IT people being self important dipsticks. They like to pretend they are defending NSA secrets. It's just a matter of them ticking some boxes on the server config screen. That's why they didn't even bother to put the password requirements on the webpage. To use your anal ogy, the lock you use on your closet door should be up to you, not mandated by someone who's never seen a closet.

OK. on a serious note as a cybersecurity person. I know the reason they're making the very strict password requirements. It's because even if it's only a website that allows you to log your stretching, it's attached to your user record which is PII and Health related so even more regulated. That means more potential for fines and risk. On top of that, popping an easy account on that website increases their risk exposure for the server getting popped, which would give the bad guys a foothold in the companies environment where much more sensitive information probably resides.

With that said, it sounds like their implementation of the controls/measures just absolutely blows goats. There are moderately friction free ways of doing this crap these days, they need to "get gud" as they would say.
 
  • 1Like
Reactions: 1 user

Hoss

Make America's Team Great Again
<Gold Donor>
31,774
26,458
OK. on a serious note as a cybersecurity person. I know the reason they're making the very strict password requirements. It's because even if it's only a website that allows you to log your stretching, it's attached to your user record which is PII and Health related so even more regulated. That means more potential for fines and risk. On top of that, popping an easy account on that website increases their risk exposure for the server getting popped, which would give the bad guys a foothold in the companies environment where much more sensitive information probably resides.
I get that it legally has to be important for them. But that doesn't mean force me to use super secure passwords, it means give me the option. Let me go up to 10000 characters and use every character in any possible language if I want to. But don't force me to. If that's the concern, I'd be all for a warning that says "your password sucks if you get hacked it's not our fault"

Is there no way whatsoever to segregate my acocunt from the rest? Are you saying that once I get logged back into my account I'll be able to hack their gibson? Seems highly unlikely. If so, send me a script. I kinda hate them right now.
 

Haus

I am Big Balls!
<Aristocrat╭ರ_•́>
21,865
90,916
I get that it legally has to be important for them. But that doesn't mean force me to use super secure passwords, it means give me the option. Let me go up to 10000 characters and use every character in any possible language if I want to. But don't force me to. If that's the concern, I'd be all for a warning that says "your password sucks if you get hacked it's not our fault"

Is there no way whatsoever to segregate my acocunt from the rest? Are you saying that once I get logged back into my account I'll be able to hack their gibson? Seems highly unlikely. If so, send me a script. I kinda hate them right now.
In this day and age we're quickly moving towards "password-less" authentication anyways. A pin code like you use on your ATM coupled with something only you would have access to (like your fingerprint on a reader, or a passkey on your personal device, or a facial recognition scan on a phone, etc...) multi-factor authentication.

The drawback is those require exposing what some people would rather not : Your face, your fingerprints, access to your personal devices, etc...

So it comes down to what level of trade off will you accept?
 

Hoss

Make America's Team Great Again
<Gold Donor>
31,774
26,458
In this day and age we're quickly moving towards "password-less" authentication anyways. A pin code like you use on your ATM coupled with something only you would have access to (like your fingerprint on a reader, or a passkey on your personal device, or a facial recognition scan on a phone, etc...) multi-factor authentication.

The drawback is those require exposing what some people would rather not : Your face, your fingerprints, access to your personal devices, etc...

So it comes down to what level of trade off will you accept?
I am already a hard pass on that shit.

But I'm not sure what that has to do with me choosing the level of security I feel is appropriate or whether I could hack their gibson once I get logged back in.
 

SeanDoe1z1

Naxxramas 1.0 Raider
7,870
19,886
I get that it legally has to be important for them. But that doesn't mean force me to use super secure passwords, it means give me the option. Let me go up to 10000 characters and use every character in any possible language if I want to. But don't force me to. If that's the concern, I'd be all for a warning that says "your password sucks if you get hacked it's not our fault"

Is there no way whatsoever to segregate my acocunt from the rest? Are you saying that once I get logged back into my account I'll be able to hack their gibson? Seems highly unlikely. If so, send me a script. I kinda hate them right now.
Ai probably has 30 ways to elevate admin access right now on your workgroup.

Go make your own account.


One customer I was staging something, it’s a super sekret stupid customer. I was just following my staging documents and making accounts…didn’t work the way I wanted, but didn’t start over. I got to the point I was going to request a vm wipe, they were so fucking done with me and I was so fucking done with them…

I just used ai to bring someone in outside all the companies, changed the stupid fucking program so it works on their stupid fucking pc, went thru testing. Kicked the fucker out and “covered”my tracks (this is the joke).


I’m past acceptance and a simple issue arises, I get access into their vm space, but the hours is wrong on access. So miffed.


account from original completely works. Finished. Hoping I never hear from them again.




what scares me this is an everyday normal occurrence. A human may find that account in like a backroom random review, but ai is going to find it instantly. Compound this nationwide and companies going to realize pretty quick the people they employ are not really equipped for the role they have.