Front Desk Questions, suggestions, site problems? Put all your site related threads in here.

MT password requirements are stupid

Thread Tools
 
Search this Thread
 
Old 01-06-2020, 10:28 AM
  #1  
y8s
2 Props,3 Dildos,& 1 Cat
Thread Starter
iTrader: (8)
 
y8s's Avatar
 
Join Date: Jun 2005
Location: Fake Virginia
Posts: 19,338
Total Cats: 573
Default MT password requirements are stupid

@Braineack tag the IB admins. I forget who they are.


Seriously, haven't we all learned that all of the bullshit symbol and character requirements for passwords are no longer the best practice for passwords? I just got the "your password is 91 days old" nag and the new requirements are the dipshit IT departments best guess at how to be secure from 2002.


Here's my prediction based on the below facts:

1. passwords must be changed every 90 days

2. passwords must be sufficiently complex, using like 5 different character types

3. passwords must not be the same as previous ones


Prediction: in about 90 days, your users will just tell you to **** off. And each time you force a new password, you'll lose more users.


The reality is that overly complicated passwords aren't that much more secure. And many systems have ditched 90 day password expirations because a post-it note with your password is pretty damn un-secure.


https://howsecureismypassword.net/

B@dd0g1! (9 hours-- fits MT requirements, pita to remember)

miatas0good4drifting (11 billion years-- easy to remember)

You@MTsuck99dicks! (7 quadrillion years-- fits MT requirements, but we can't all have the same awesome password...)
y8s is offline  
Old 01-06-2020, 10:39 AM
  #2  
Senior Member
 
msmola2002's Avatar
 
Join Date: Aug 2017
Location: Norwich NY
Posts: 635
Total Cats: 322
Default

@Robb M. is your friendly admin, I believe.
msmola2002 is offline  
Old 01-06-2020, 11:05 AM
  #3  
IB Staff
 
Robb M.'s Avatar
 
Join Date: May 2012
Posts: 170
Total Cats: 12
Default

hey @y8s members don't have a 90 day password requirement, only super mods do. As for the complexity stuff, that's all been demanded by the new CCPA that came into effect on Jan 1. I updated the expiry to 180 days.
Robb M. is offline  
Old 01-06-2020, 11:28 AM
  #4  
Elite Member
iTrader: (5)
 
Erat's Avatar
 
Join Date: Oct 2011
Location: Detroit (the part with no rules or laws)
Posts: 5,677
Total Cats: 800
Default

They made us all do that at work. Now everyone's password is "Password123!". We've been getting alerts for "phishing" every other week since the change.
Erat is offline  
Old 01-06-2020, 12:22 PM
  #5  
y8s
2 Props,3 Dildos,& 1 Cat
Thread Starter
iTrader: (8)
 
y8s's Avatar
 
Join Date: Jun 2005
Location: Fake Virginia
Posts: 19,338
Total Cats: 573
Default

Believe me, I know. We are NIST compliant here and I have to use some dipshit third party app for 2FA in addition to all the password BS. The difference is the paycheck.

180 days is better, thank you.

And believe me I also know all about the california privacy laws. My friend is a lawyer writing them for all the big tech firms. I send her text messages to express my displeasure.
y8s is offline  
Old 01-06-2020, 12:25 PM
  #6  
IB Staff
 
Robb M.'s Avatar
 
Join Date: May 2012
Posts: 170
Total Cats: 12
Default

consider yourself lucky, i have to use 2fa to get into any of our communities and again to get into the adminCP 🙃
Robb M. is offline  
Old 01-06-2020, 03:41 PM
  #7  
Boost Czar
iTrader: (62)
 
Braineack's Avatar
 
Join Date: May 2005
Location: Chantilly, VA
Posts: 79,498
Total Cats: 4,080
Default

i still have the same password here from like 2006.
Braineack is offline  
Old 01-06-2020, 03:46 PM
  #8  
IB Staff
 
Robb M.'s Avatar
 
Join Date: May 2012
Posts: 170
Total Cats: 12
Default

looks like admins don't have a password expiry set, so it makes absolutely no sense that super mods do. @y8s have you always had to rotate your password every 90 days?
edit; mods also have a 90 day expiry set.
Robb M. is offline  
Old 01-06-2020, 04:00 PM
  #9  
y8s
2 Props,3 Dildos,& 1 Cat
Thread Starter
iTrader: (8)
 
y8s's Avatar
 
Join Date: Jun 2005
Location: Fake Virginia
Posts: 19,338
Total Cats: 573
Default

I can't recall how long, but it probably coincides with the IB takeover or maybe the last big version upgrade of the forum software.

y8s is offline  
Old 01-06-2020, 04:01 PM
  #10  
IB Staff
 
Robb M.'s Avatar
 
Join Date: May 2012
Posts: 170
Total Cats: 12
Default

limits removed.
Robb M. is offline  
Old 01-06-2020, 05:16 PM
  #11  
mkturbo.com
iTrader: (24)
 
shuiend's Avatar
 
Join Date: May 2006
Location: Charleston SC
Posts: 15,177
Total Cats: 1,681
Default

Originally Posted by Robb M.
looks like admins don't have a password expiry set, so it makes absolutely no sense that super mods do. @y8s have you always had to rotate your password every 90 days?
edit; mods also have a 90 day expiry set.

I had Nolan turn that off years ago.
shuiend is offline  
Old 01-09-2020, 02:13 PM
  #12  
y8s
2 Props,3 Dildos,& 1 Cat
Thread Starter
iTrader: (8)
 
y8s's Avatar
 
Join Date: Jun 2005
Location: Fake Virginia
Posts: 19,338
Total Cats: 573
Default

thanks Robb.
y8s is offline  
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
IB Nolan
Front Desk
125
02-15-2019 03:26 PM
EO2K
Front Desk
25
04-01-2013 12:11 PM
ThatGuy85
Insert BS here
14
01-07-2011 12:17 PM



Quick Reply: MT password requirements are stupid



All times are GMT -4. The time now is 01:16 AM.