1
A senior sysadmin told me my password policy was too strict and I figured out he was right after 3 lockouts in one day
He said nobody will use a 20-character password with special chars if they have to type it on a phone, so I cut it to 14 characters and added MFA instead, has anyone else found that shorter rules actually made people stop reusing passwords?
2 comments
Log in to join the discussion
Log In2 Comments
oliver228d ago
Has anyone actually looked at how MFA fatigue attacks have changed since you made that switch? Because I've seen a lot of places move to shorter passwords plus MFA, then users start blindly approving push notifications without even reading them. So your 14-character rule might stop sticky notes, but now you're trading one problem for another that's way harder to catch.
6
nobody will use a 20-character password" yeah I went through the same thing, my users just wrote them on sticky notes.
-1