Amicitas@lemmy.world to Technology@lemmy.worldEnglish · 2 months agoNIST proposes barring some of the most nonsensical password rulesarstechnica.comexternal-linkmessage-square36fedilinkarrow-up1316arrow-down11file-text
arrow-up1315arrow-down1external-linkNIST proposes barring some of the most nonsensical password rulesarstechnica.comAmicitas@lemmy.world to Technology@lemmy.worldEnglish · 2 months agomessage-square36fedilinkfile-text
minus-squarejj4211@lemmy.worldlinkfedilinkEnglisharrow-up17·2 months agoMeanwhile, my company has systems insisting on expiring ssh keys after 90 days…
minus-squareTBi@lemmy.worldlinkfedilinkEnglisharrow-up5·2 months agoMy company blocked ssh keys in favour of password + 2FA. Honestly I don’t mind the 2FA since we use yubikeys, but wouldn’t ssh key + 2FA be better?
minus-squarejj4211@lemmy.worldlinkfedilinkEnglisharrow-up1·2 months agoAll well and good when ssh activity is anchored in a human doing interactive stuff, but not as helpful when there’s a lot of headless automation that has to get from point a to point b.
minus-squareTBi@lemmy.worldlinkfedilinkEnglisharrow-up2·2 months agoYep. All the headless automation broke…
minus-squareAnUnusualRelic@lemmy.worldlinkfedilinkEnglisharrow-up5·2 months agoFools! You have to expire the whole system! Reinstall everything every 90 days. It’s the only way.
minus-squarejj4211@lemmy.worldlinkfedilinkEnglisharrow-up2·2 months agoYou are going to give them ideas… Ironically, reinstall the whole system, make sure to add some CrowdStrike, SolarWinds, and Ivanti for security and management though…
Meanwhile, my company has systems insisting on expiring ssh keys after 90 days…
My company blocked ssh keys in favour of password + 2FA. Honestly I don’t mind the 2FA since we use yubikeys, but wouldn’t ssh key + 2FA be better?
All well and good when ssh activity is anchored in a human doing interactive stuff, but not as helpful when there’s a lot of headless automation that has to get from point a to point b.
Yep. All the headless automation broke…
Fools! You have to expire the whole system!
Reinstall everything every 90 days. It’s the only way.
You are going to give them ideas…
Ironically, reinstall the whole system, make sure to add some CrowdStrike, SolarWinds, and Ivanti for security and management though…