Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Claudius Link
Claudius Link
@realn2s@infosec.exchange  路  activity timestamp 2 weeks ago

A bit more details

Imagine you identified users who have a weak password, reused their password, or use a password from known breaches.

I would like to notify them that they need to change their password and at the same time increase that chance that they pick a good password when they are asked (or forced) to change their password.

As the password is for their central account a password safe is of limited use 馃槵
As they can't access their company system without the password, they would need a password safe on another (non-company) device

#cybersecurity #fedipower

  • Copy link
  • Flag this post
  • Block
amy
amy
@amy@fedi.amy.mov replied  路  activity timestamp 2 weeks ago

@realn2s@infosec.exchange i鈥檓 curious how you would force a change but also allow access to this tool on the company device

at least for a windows domain you have to do all of this on the lock screen..?

  • Copy link
  • Flag this comment
  • Block
Claudius Link
Claudius Link
@realn2s@infosec.exchange replied  路  activity timestamp 2 weeks ago

A bit more details

Imagine you identified users who have a weak password, reused their password, or use a password from known breaches.

I would like to notify them that they need to change their password and at the same time increase that chance that they pick a good password when they are asked (or forced) to change their password.

As the password is for their central account a password safe is of limited use 馃槵
As they can't access their company system without the password, they would need a password safe on another (non-company) device

#cybersecurity #fedipower

  • Copy link
  • Flag this comment
  • Block
Claudius Link
Claudius Link
@realn2s@infosec.exchange replied  路  activity timestamp last week

Here some resources on secure and usable passwords:

Lorrie Cranor's work at https://lorrie.cranor.org/ , the CyLab Usable Privacy and Security Laboratory (CUPS) https://cups.cs.cmu.edu/ and her #TedTalk https://www.ted.com/talks/lorrie_faith_cranor_what_s_wrong_with_your_pa_w0rd

I will add more resources over time

  • Copy link
  • Flag this comment
  • Block
Brahms
Brahms
@brahms@chaos.social replied  路  activity timestamp 2 weeks ago

@realn2s I mean the obvious answer would be pivoting to passkeys and passwordless auth?

is there any reason why thats not applicable here?

  • Copy link
  • Flag this comment
  • Block
d@nny disc@ mc虏
d@nny disc@ mc虏
@hipsterelectron@circumstances.run replied  路  activity timestamp 2 weeks ago

@realn2s this is a really good and thoughtful idea

  • Copy link
  • Flag this comment
  • Block
d@nny disc@ mc虏
d@nny disc@ mc虏
@hipsterelectron@circumstances.run replied  路  activity timestamp 2 weeks ago

@realn2s i literally use a script in emacs lisp for this purpose

  • Copy link
  • Flag this comment
  • Block
blackopelves
blackopelves
@blackopelves@infosec.exchange replied  路  activity timestamp 2 weeks ago

@realn2s oh, and once you have used this tool the password doesn't age out anymore.

  • Copy link
  • Flag this comment
  • Block
blackopelves
blackopelves
@blackopelves@infosec.exchange replied  路  activity timestamp 2 weeks ago

@realn2s we created an internal web-based tool that combines the zxcvbn lib, the hibp password compromise check, the AD policy an internal self maintained blocklist and some compliance theater boxes into an interactive password check & change tool. Especially zxcvbn helps...

  • Copy link
  • Flag this comment
  • Block
Claudius Link
Claudius Link
@realn2s@infosec.exchange replied  路  activity timestamp 2 weeks ago

@blackopelves
That is a very good pointer, thanks 馃檹馃徎

  • Copy link
  • Flag this comment
  • Block
Orlando Gentil
Orlando Gentil
@OG@bolha.us replied  路  activity timestamp 2 weeks ago

@realn2s if one is taking the time to install a password generator, they could take the opportunity to introduce a password manager like https://keepassxc.org (as per the requirements you asked). It might be challenging to remember randomly generated passwords.

  • Copy link
  • Flag this comment
  • Block
23Ro
23Ro
@23R0@mastodon.social replied  路  activity timestamp 2 weeks ago

@realn2s Does the password need to be generated on mobile as well or are the users primarily on PC/Mac/Win?

  • Copy link
  • Flag this comment
  • Block
Claudius Link
Claudius Link
@realn2s@infosec.exchange replied  路  activity timestamp 2 weeks ago

@23R0
I think primary PC/laptop would be sufficient

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About 路 Code of conduct 路 Privacy 路 Users 路 Instances
Bonfire social 路 1.0.1-alpha.40 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct