home.social

#securitythroughobscurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securitythroughobscurity, aggregated by home.social.

  1. The following rules apply for user passwords:

    * Passwords must be changed every year
    * Passwords are checked against a list of known weak passwords
    * Previously used passwords must not be reused
    * Passwords must be at least 16 characters long
    * Passwords must consist of at least three of the following groups
    * lower case letters
    * upper case letters
    * digits
    * emojis coding for emotion
    * mostly red emojis
    * one half of the simplified Japanese alphabet
    * symbols that conjure Lucifer
    * Passwords must neither begin or end with a number (because, why not?)
    * Passwords must not contain the name of your mom
    * Passwords must not contain any words of our secret "dictionary" (like the name of the company but also Football Clubs' deputy managers' wife's/husband's nicknames)
    * Passwords sum of the characters' UTF codes must be divisible by seven, 11 or any prime number larger than 1000.

    On the bright side: Typing your password *is* still working time, so you get paid. You can also now clame a law degree on your CV.

    #ActiveDirectory #SecurityThroughObscurity #Passwords #PasswordPolicy

  2. I just remembered about port knocking, it is by far the most spy movie security-through-obscurity gate of cybersec

    You must know the secret knock

    ...and of course now it's configured on my VPS on top of the usual SSH restrictions (no root login, attempt limit, PK auth, etc)

    #ssh #linux #server #CyberSecurity #cybersec #securitythroughobscurity #securitybyobscurity