• whoisearth@lemmy.ca
    link
    fedilink
    English
    arrow-up
    8
    ·
    23 hours ago

    Security is all theatre. When NIST says make secure passwords and never change them but your fortune 500 infosec policy tells you to rotate your password every 30 days?

    LOL

      • whoisearth@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        6 hours ago

        Yes. Pwd change should only be on evidence of compromise assuming you have made a secure password.

    • uncouple9831@lemmy.zip
      link
      fedilink
      English
      arrow-up
      5
      ·
      22 hours ago

      And those companies’ policies cascade out because of the incestuous nature of company boards. Some dumbass who is C__ at one company and member of the board at another says you gotta do the same to be compliant and since it’s all theater they comply rather than push back. Corporations are dumb.