• superkret@feddit.org
    link
    fedilink
    arrow-up
    8
    arrow-down
    1
    ·
    3 months ago

    Sorry, those rules come from our cybersecurity insurance, or some compliance rules.
    We hate them as much as you do.

    • Windex007@lemmy.world
      link
      fedilink
      arrow-up
      3
      arrow-down
      2
      ·
      3 months ago

      Then why are they different between systems? Do you have different insurers per application?

      • superkret@feddit.org
        link
        fedilink
        arrow-up
        6
        ·
        3 months ago

        Those other applications come from an external vendor, we only provide the VM to run them.
        We hate those even more than you do.

          • Honytawk@lemmy.zip
            link
            fedilink
            arrow-up
            2
            arrow-down
            1
            ·
            3 months ago

            Every single issue that occurs with those applications gets thrown in our laps to fix.

            This includes all of yours as well as all your colleagues.

            • Windex007@lemmy.world
              link
              fedilink
              arrow-up
              3
              arrow-down
              2
              ·
              3 months ago

              See I think this is where in general people in it misunderstand the impact.

              Like, if it’s -40 and your furnace breaks, who is having the worse day, you or the furnace repair man?

              The repair man might be grumbling because they have to do their job, but you’re grumbling because you’re freezing. You both might be grumbling, but by way of impact there is a massive asymmetry in impact.

              • Honytawk@lemmy.zip
                link
                fedilink
                arrow-up
                2
                arrow-down
                1
                ·
                3 months ago

                But that is only looking from one perspective.

                That repair man is going around to many peoples freezing houses. They are also freezing their butts off all day. And not just one period in winter, every single day of winter.

                And when they fix a house, they don’t get to enjoy the warmth afterwards. They have to go to the next freezing house.

                Understand that impact.

                • Windex007@lemmy.world
                  link
                  fedilink
                  arrow-up
                  2
                  arrow-down
                  1
                  ·
                  3 months ago

                  I believe I understand the perspectives, but I’m unconvinced that there isn’t asymmetry. It’s one person’s job.

                  Like, I’ll whine all day about my job. But I’m under no illusions that I didn’t sign up for it, and I’m extremely cognizant that while it’s a bummer that I have to do my job, I understand that the people I support are having a worse day than I am. I’m not doing anyone a favour, I’m doing my job.

      • Heydo@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        3 months ago

        What applications do you have that IT controls the password requirements for?

        IT controls your AD credential requirements in most cases and that’s pretty much it. It sounds like your employer needs to implement an SSO solution.

        • Windex007@lemmy.world
          link
          fedilink
          arrow-up
          2
          ·
          edit-2
          3 months ago

          It is the AD credentials. It’s a fortune 500 company and it doesn’t even come close to NIST recommendations.

          We have like 3 different ADs as a result of mergers and acquisitions, and the requirements are all different.

            • Windex007@lemmy.world
              link
              fedilink
              arrow-up
              2
              ·
              3 months ago

              One of them is EXACTLY 8 ASCII characters, may not contain any English dictionary word, no repeating character. At least 1 number, and at least 1 special characters. Just obliterates the search space.