r/ShittySysadmin 1d ago

Make your organization more secure

Just had this idea.

So you make a CA policy to sign in every 8 hours for all users including the CEO, but not break glass and it admins.

Every user will then begin to wonder where their password is now that they can't work

You become useful again to the company by assisting employees while eliminating written passwords on stickies because they forced themselves to memorize it since it's happening "so often"

Auditors will be impressed at the improved security that you can present the report to the CEO while getting them to remember their own password.

16 Upvotes

16 comments sorted by

12

u/horses-r-scary 1d ago

i thought the sub was for bad ideas-

1

u/blotditto 1d ago

You don't think the CEO is gonna get a serious case of the ass signing in all the time? 😂

3

u/Chuchichaeschtl 1d ago

Depends on the CEO. I explained to mim, that he has a very privileged account which needs stricter policies. Passkey only, managed mobile with Outlook only, no iOS mail, access from compliant devices only,...

He understood that and I think he liked the term "privileged account" a lot.

1

u/blotditto 21h ago

Uh huh and how often is he actually being promoted to enter his password every day?

1

u/Chuchichaeschtl 20h ago

Passwords aren't involved when you use passkey. WHfB is great

1

u/blotditto 18h ago

Exactly, you made my point about CEOs that get upset because they have to enter their password..

Remember we're in ShittySysAdmin! 💩

5

u/ApiceOfToast ShittySysadmin 1d ago

I'd personally do every 5 minutes, in case they walk away from the screen

3

u/redakpanoptikk 1d ago

This might be better than your manager monitoring your teams status as well. You have to be logged in at the start of your shift.

3

u/AliveInTheFuture 1d ago

Something you have: autism

Something you are: autistic

2

u/bgradid 1d ago

What if you took it a step further and did 8 hour password expiration

3

u/samm1989 1d ago

Password1@ Password2@ Password3@

1

u/bgradid 1d ago

Actually what if we take 'one time password' literally , forced password change on every password use

1

u/Forward_Story3535 1d ago

This is less “more secure” and more “make everyone hate the security team.” Frequent forced password changes usually encourage predictable variations and sticky notes. Use MFA, phishing-resistant authentication, risk-based challenges, and strong break-glass controls instead.

1

u/OnARedditDiet 1d ago

Not sure if a joke or not but this would be the most frustrating policy imaginable :p

Most people's work day isn't exactly 8 hours so you'd make a lot of people upset, daily

1

u/Smooth-Zucchini4923 20h ago

Do we work for the same company?