There have been multiple accounts created with the sole purpose of posting advertisement posts or replies containing unsolicited advertising.

Accounts which solely post advertisements, or persistently post them may be terminated.

Thousands of employees in the US Department of the Interior are using accounts that are easily hacked

Thousands of employees in the US Department of the Interior are using accounts that are easily hacked::The Interior Department is tasked with protecting the country’s natural resources, like gas pipelines. Hundreds of its senior officers even used “password-1234” on their accounts.

FlyingSquid ,
@FlyingSquid@lemmy.world avatar

That’s amazing! That’s the same password I have on my luggage!

n3cr0 ,

They did it all correct: Characters lower case and upper case, numbers and symbols. 🥴

totallynotfbi ,

Greenblatt also noted that 99.99% of the 18,000 accounts that staff cracked met the Department’s password complexity requirements — including “Password-1234.”

If a password as rudimentary as “password-1234” satisfies the complexity requirements, I think that some blame should be shared by the IT team in charge of account security…

Kalkaline ,
@Kalkaline@programming.dev avatar

Passwords are the weak link here. Microsoft figured out all you need to keep an account secure is 2FA, to the point they offer password-free account access.

Cqrd ,

My wife works for the govt and says the password rules also require being changed every 90 days for her, which has been proven to cause weak passwords and/or people writing them down because they can’t remember their current one.

The govt uses pretty antiquated password security guidelines, this article is no surprise.

Ilikepornaddict ,

This is the most likely cause. My work has this too, but it’s every 30 days, and you can’t use the same password as any of your last 21 passwords. Which means I need 21 unique passwords. So it’s Password1, Pasword2, etc until Password 21, when I then loop back around. Great job security team!

TornadoRex ,
@TornadoRex@lemmy.world avatar

Which also means your company is storing your old passwords which is a big security issue

Ilikepornaddict ,

My company’s IT department is terrible. Nothing is done right. And they’re a multi-billion dollar company.

Blamemeta ,

Password-1234 is over 8 characters, has an uppercase character, a lowercase character, a number, and a special character.

Looks fine to me.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • [email protected]
  • random
  • lifeLocal
  • goranko
  • All magazines