19
Can we talk about why everyone still uses "password123" in 2024?
I checked my company's leaked credentials on haveibeenpwned last week and 14 out of 40 accounts still had the same password from 2019. Two of those were managers who got phishing training twice. What's the point of all those security webinars if nobody actually changes their habits?
2 comments
Log in to join the discussion
Log In2 Comments
evahenderson18d ago
Training fatigue is real, but honestly, forcing everyone to change a password every 90 days just makes people pick garbage like "Password6!" with a new number. Makes more sense to let people stick with a strong one they actually remember than to keep cycling bad habits.
1
ivan_murphy8018d ago
@evahenderson yeah "Password6!" is a perfect example lol. It reminds me though, NIST actually updated their guidelines a while back to say periodic changes aren't needed unless there's a breach, so you're spot on about the old 90 day rule being outdated.
2