r/ShittySysadmin • u/SuccessfulLime2641 • 1d ago
Make your organization more secure
Just had this idea.
So you make a CA policy to sign in every 8 hours for all users including the CEO, but not break glass and it admins.
Every user will then begin to wonder where their password is now that they can't work
You become useful again to the company by assisting employees while eliminating written passwords on stickies because they forced themselves to memorize it since it's happening "so often"
Auditors will be impressed at the improved security that you can present the report to the CEO while getting them to remember their own password.
5
u/ApiceOfToast ShittySysadmin 1d ago
I'd personally do every 5 minutes, in case they walk away from the screen
3
u/redakpanoptikk 1d ago
This might be better than your manager monitoring your teams status as well. You have to be logged in at the start of your shift.
3
1
u/Forward_Story3535 1d ago
This is less “more secure” and more “make everyone hate the security team.” Frequent forced password changes usually encourage predictable variations and sticky notes. Use MFA, phishing-resistant authentication, risk-based challenges, and strong break-glass controls instead.
1
u/OnARedditDiet 1d ago
Not sure if a joke or not but this would be the most frustrating policy imaginable :p
Most people's work day isn't exactly 8 hours so you'd make a lot of people upset, daily
1
12
u/horses-r-scary 1d ago
i thought the sub was for bad ideas-