• 0 Posts
  • 2 Comments
Joined 3 years ago
cake
Cake day: June 20th, 2023

help-circle
  • Interestingly, that was the episode that made me stop watching.

    I suspect I just don’t normally like watching shows about miserable people making other miserable people even more miserable, which made the fact that I really enjoyed Boardwalk Empire a surprise.

    Guess there must be some other element to it.


  • PIN is the best way to go there. It only works on that one machine, although you can technically set the same PIN again on another computer.

    I believe the typical intent is as follows:

    1. It is now possible to brute force things that were previously considered “complex” passwords in a semi-reasonable amount of time.
    2. This necessitates longer and more complex passwords
    3. People can’t remember those so they have a tendency to write them down or do other relatively insecure things with them.
    4. Forgotten passwords can generate a lot of helpdesk calls and are also an attack vector
    5. If we insist on really complex passwords that are too long to reasonably brute force with current technology, we need a way for users to log in that’s not going to make 3 and 4 a major issue.
    6. If the simpler PIN method is locked to a per machine basis, it matters a lot less if the PIN is compromised because you also need physical access to the computer or the PIN is useless.

    This should, in theory, allow workplaces to set requirements for really complex passwords that only need to be reset once a year or so, without breaking helpdesk, inconveniencing users, or leaving gaping security holes.

    Whether or not that all happens depends on the workplace, but that’s the general thought process in most of the places I’ve worked where a modicum of sense prevails