• SwiftOnSecurity Profile Picture

    SwiftOnSecurity @SwiftOnSecurity

    6 years ago

    Microsoft is proposing to remove password expiration as a recommended configuration for Windows systems

    mniehaus Profile Picture

    Michael Niehaus @mniehaus

    6 years ago

    Microsoft is proposing to remove password expiration as a recommended configuration for Windows systems

    4 157 273 0 19

    53 255 805 0 20
  • SwiftOnSecurity Profile Picture

    SwiftOnSecurity @SwiftOnSecurity

    6 years ago

    [UPDATE] Microsoft recommendation to NOT force user password changes on a schedule is now their official published security guidance for Windows customers. This obviates decades of common-knowledge, in response to evidence it’s actually harmful to security blogs.technet.microsoft.com/secguide/2019/…

    46 852 1K 0 64
  • SwiftOnSecurity Profile Picture

    SwiftOnSecurity @SwiftOnSecurity

    6 years ago

    Although NIST and others precede this and deserve that credit, I think it’s worth taking a moment to recognize this moment in time as truly a fundamental change in the industry.

    13 53 351 0 2
  • Maliciouslink Profile Picture

    Socially Distant Jerry @Maliciouslink

    6 years ago

    @SwiftOnSecurity My counterpoint: Basically the guidance is not ONLY disabling password expiration. Read the and implement ALL of the guidance. infosec.engineering/requiring-peri…

    4 16 54 0 7
  • migueldeicaza Profile Picture

    Miguel de Icaza ᯅ🍉 @migueldeicaza

    6 years ago

    @SwiftOnSecurity @Aykay It is a gift of the gods - the policy is also internal.

    0 1 7 0 0
  • cigitalgem Profile Picture

    Gary McGraw @cigitalgem

    6 years ago

    @SwiftOnSecurity @SteveBellovin Ha ha ha ha ha. Hey corporate security morons, check this out.

    0 1 0 0 0
  • shoghicp Profile Picture

    @[email protected] on Fediverse / @shoghicp

    6 years ago

    @SwiftOnSecurity They also adjusted their internal policy to be one year password change instead of 70 day forced password changes.

    0 0 2 0 0
  • knilch0r Profile Picture

    🭪 🭍🭲🬲 🮫 🬛🬕 🮲🮳 @knilch0r

    6 years ago

    @SwiftOnSecurity If commercial Windows customers handle that guidance the same way they handle updates, it's only a matter of a few decades until it's widespread practice.

    0 2 44 0 0
  • TryCatchHCF Profile Picture

    Try Catch HCF (@[email protected]) @TryCatchHCF

    6 years ago

    @SwiftOnSecurity And let's face it - Most scheduled password updates seem to result in the user adding either another '!' or the next number in the sequence to the existing password. Not exactly raising the entropy there. 😏

    4 0 36 0 0
  • Deonizm Profile Picture

    Cutty Flam @Deonizm

    6 years ago

    @SwiftOnSecurity "Periodic password expiration is an ancient and obsolete mitigation of very low value, and we don’t believe it’s worthwhile for our baseline to enforce any specific value." - Microsoft (@AaronMargosis) Here it is. The hill I'm gonna die on come Monday.

    1 3 16 0 0
  • rogue_analyst Profile Picture

    d:\erek_klein 👽 @rogue_analyst

    6 years ago

    @SwiftOnSecurity "... if your users are the kind who are willing to answer surveys in the parking lot that exchange a candy bar for their passwords, no password expiration policy will help you." - Microsoft (@AaronMargosis) ^ This is gold. GOLD!

    2 4 10 0 0
  • chriskoch99 Profile Picture

    Chris Koch @chriskoch99

    6 years ago

    @SwiftOnSecurity +1 for "obviates"

    2 0 16 0 0
  • RidicBowe Profile Picture

    GERWALK IT OUT✊🏽🇵🇸 keep a 📯 on me, that Kamasi @RidicBowe

    6 years ago

    @SwiftOnSecurity NIST passed this recommendation last year, waiting it to filter down through enterprise

    1 1 9 0 0
  • LorettoDave Profile Picture

    Dave Rand (LorettoDave most places) @LorettoDave

    6 years ago

    @SwiftOnSecurity Woohoo! I wonder if the PCI council are planning to change any time soon.

    1 0 6 0 0
  • AdamFowler_IT Profile Picture

    Adam Fowler @AdamFowler_IT

    6 years ago

    @SwiftOnSecurity @MaarNu Still don't agree that it's as clear as 'password changes are bad', it's more that passwords are bad.

    1 0 6 0 0
  • werrett Profile Picture

    Jonathan Werrett @werrett

    6 years ago

    @SwiftOnSecurity Now how long before the compliance standards and auditors catch-up?

    0 1 2 0 0
  • darkgrue Profile Picture

    Dark Grue @darkgrue

    6 years ago

    @SwiftOnSecurity NIST 800-63B makes that very same recommendation (and probably was the document that prompted that policy change from MS). Mandatory change in the face of evidence of compromise, is still standard, of course.

    1 0 4 0 0
  • JoeNewstrom Profile Picture

    Joe Newstrom @JoeNewstrom

    6 years ago

    @SwiftOnSecurity WHY ON EARTH has MSFT not purchased a password manager and tightly integrated it with AAD, Win10, and Office 365? This is the most obvious acquisition. There are 3 that are possible, KeePass, Dashlane, and 1Password. LastPass is great but I don't see prying it away from LogMeIn.

    0 0 4 0 0
  • ablho Profile Picture

    Ablho 🎈 ؟🇵🇸🇮🇪 🇧🇴🍉 @ablho

    6 years ago

    @SwiftOnSecurity When forced to change passwords people tend to use “something easy to remember followed by a number”.

    0 1 2 0 0
  • infinitywaltz Profile Picture

    Matthew J. @infinitywaltz

    6 years ago

    @SwiftOnSecurity "Guess I'll just use the same password but with a THIRD exclamation point."

    0 0 4 0 0
  • JuanIsidro Profile Picture

    Juan @JuanIsidro

    6 years ago

    @SwiftOnSecurity Fricking finally. Forced changes just lead to users creating simpler passwords, in my experience.

    1 1 1 0 0
  • PulseAwakening Profile Picture

    Challenger @PulseAwakening

    6 years ago

    @SwiftOnSecurity Awesome! I expect that by 2259 my workplace will get around to adopting this practice, just after they have finished transitioning the last MS Acces DB to a SQL Server 2008 instance.

    0 0 3 0 0
  • dpeters11 Profile Picture

    David Peterson @dpeters11

    6 years ago

    @SwiftOnSecurity now I just need clients of ours to stop mandating password expiration in their security requirements for us.

    0 0 3 0 0
  • Andronian Profile Picture

    andro @Andronian

    6 years ago

    @SwiftOnSecurity Any idea what this should mean for shared accounts, or machine service accounts? This seems to address user passwords specifically

    1 0 2 0 0
  • damienmaillard Profile Picture

    dmail @damienmaillard

    6 years ago

    @SwiftOnSecurity @__jakub_g FI-NA-LY so sick of this nonsense

    0 0 1 0 0
  • lclaytonparker Profile Picture

    Lee Parker @lclaytonparker

    6 years ago

    @SwiftOnSecurity Common knowledge isn't...common. There is published research for and against regularly changing passwords.

    0 0 1 0 0
  • rs6w Profile Picture

    AC @rs6w

    6 years ago

    @SwiftOnSecurity Password cycling is dumb. Have different passwords for each site.

    0 0 1 0 0
  • S_de_Incognito Profile Picture

    Sergio @S_de_Incognito

    6 years ago

    @SwiftOnSecurity Wait so scheduled password changes are good or not?

    2 0 1 0 0
  • MLDataTorturer Profile Picture

    Nondescript @MLDataTorturer

    6 years ago

    @SwiftOnSecurity Why are we still using passwords?

    1 0 0 0 0
  • DrolSecurity Profile Picture

    DROL Security @DrolSecurity

    6 years ago

    @SwiftOnSecurity Someone had better explain this to the PCI Security Standards Council. PCI-DSS V 3.2.1 8.2.4 . @PCISSC

    DrolSecurity tweet picture

    0 0 0 0 0
    Download Image
  • DavidSiddall7 Profile Picture

    David Siddall @DavidSiddall7

    5 years ago

    @SwiftOnSecurity @alistairstead46 i guess the temptation to change from password 1 to password 2 is a little too much!

    0 0 0 0 0
  • 7777gggg34 Profile Picture

    7777gggg34 @7777gggg34

    6 years ago

    @SwiftOnSecurity Long, long time coming.

    0 0 0 0 0
  • steve_infosec Profile Picture

    Steve Johnson @steve_infosec

    6 years ago

    @SwiftOnSecurity This is a great move, I've been trying to get this through at work but had lots of resistance. Now a big and recognisable name such as Microsoft is behind it, we should be good to go! With the caveat that, standards like PCI still require password changes every 90 days!

    0 0 0 0 0
  • usrbinawk Profile Picture

    /usr/bin/awk @usrbinawk

    6 years ago

    @SwiftOnSecurity My ISO will have a brain aneurysm if he reads that.

    0 0 0 0 0
  • bieberium Profile Picture

    Pʜɪʟ! @bieberium

    6 years ago

    @SwiftOnSecurity What would be your recommendation for orgs who currently cannot reliably monitor for password misuse? I argue that expiering the password in this case is better than blindly following recommendations...

    0 0 0 0 0
  • ordietrying Profile Picture

    anthony @ordietrying

    6 years ago

    @SwiftOnSecurity @KSU_IT_Threats

    0 0 0 0 0
  • FeNi64 Profile Picture

    http://mastodon.social/@FeNi64 bsky: FeNi @FeNi64

    6 years ago

    @SwiftOnSecurity I have to log into work's performance review site every three months. The password expires after two months. 😔

    0 0 0 0 0
  • Download Image
    • Privacy
    • Term and Conditions
    • About
    • Contact Us
    • TwStalker is not affiliated with X™. All Rights Reserved. 2024 www.instalker.org

    twitter web viewer x profile viewer bayigram.com instagram takipçi satın al instagram takipçi hilesi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al sosyalgram takipçi satın al instagram ücretsiz takipçi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al metin2 metin2 wiki metin2 ep metin2 dragon coins metin2 forum metin2 board popigram instagram takipçi satın al takipçi hilesi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al buyfans buy instagram followers buy instagram likes buy instagram views buy tiktok followers buy tiktok likes buy tiktok views buy twitter followers buy telegram members Buy Youtube Subscribers Buy Youtube Views Buy Youtube Likes forstalk postegro web postegro x profile viewer