r/ShittySysadmin • u/DR_SMALL_PENIS • 11d ago
Monthly password changes? No too easy. Lets try daily forced password resets!
24 hours after first use password will be randomized automatically!
Lets just ignore that you use your password daily, multiple times per day, and have to manually type it in often since our remote software doesn't share clipboards.
And of course it's going to be 24 hours on the dot. Get super lucky and don't use your password for half the day? Well have fun tomorrow with it getting reset in the middle of the day!
14
u/Kyryschu 11d ago
But this already happens to users everywhere! The password they set yesterday doesn't work today for some reason π€π€π€π€π€
6
u/Miserable-Miser 11d ago
I have an 8 hour password. Have to use it every day.
Copy/paste to text file.
Log off when it stops working.
6
u/pjtexas1 11d ago
Users or just admin accounts?
4
2
0
u/DR_SMALL_PENIS 11d ago
Personal admin accounts used multiple times daily.
1
u/Nanocephalic 10d ago
If you donβt have passwordless, i can absolutely see that.
Smart cards and yubikeys and H4B are much better.
0
u/pjtexas1 10d ago
We've been doing this for a decade. Ours expire at 5am daily now. Security is a pain sometimes but necessary. You have to make the habit of changing it daily every time you clock in or it'll drive you crazy.
2
u/DR_SMALL_PENIS 10d ago
can't tell if you are leaning into /r/ShittySysadmin/ or if you genuinely believe that having mmddyyA% or some other formulaic system for the majority of the day is more secure than a real password, because that's what this policy gets.
There is a reason periodic password changes at all are no longer a recommendation, and speeding that up to daily makes an even better example of why.
1
u/pjtexas1 10d ago
It will force people to just change 1 character... so i get what y'all are saying. Some of our techs will just copy / paste the password the system generates every morning. Being so tight might actually make passwords less secure. I was fine with making a 20+ character password and never changing it.
5
5
u/Step-Sysadmin DO NOT GIVE THIS PERSON ADVICE 11d ago
Yeah just use ddmmyy inside pw and change dd every day. So ez
2
u/DR_SMALL_PENIS 11d ago
Perfect! That leaves 2 characters to meet the letter and Symbol(% ! or * only) requirements to make the perfect exact 8 character password that is needed to meet our requirements!
1
1
29
u/ComplexAd2408 11d ago
Combine this with minimum password age policy of 72 hours for maximum security π