O
1

A senior sysadmin told me my password policy was too strict and I figured out he was right after 3 lockouts in one day

He said nobody will use a 20-character password with special chars if they have to type it on a phone, so I cut it to 14 characters and added MFA instead, has anyone else found that shorter rules actually made people stop reusing passwords?
2 comments

Log in to join the discussion

Log In
2 Comments
oliver2
oliver228d ago
Has anyone actually looked at how MFA fatigue attacks have changed since you made that switch? Because I've seen a lot of places move to shorter passwords plus MFA, then users start blindly approving push notifications without even reading them. So your 14-character rule might stop sticky notes, but now you're trading one problem for another that's way harder to catch.
6
haydenbutler
haydenbutler28d agoTop Commenter
nobody will use a 20-character password" yeah I went through the same thing, my users just wrote them on sticky notes.
-1