14
That sysadmin who told me to stop using password managers was wrong in 2019
My old boss at a Denver MSP swore password managers were a single point of failure and pushed us to memorize 12 different rotating passwords, but after we got hit with a credential stuffing attack that locked out 40 accounts in one morning, I switched everyone to Bitwarden and we haven't had a breach since, so has anyone else had to override a senior IT person's outdated advice?
1 comments
Log in to join the discussion
Log In1 Comment
the_miles28d ago
That old boss sounds like he was playing security roulette with everyone's sanity. Twelve rotating passwords? Man, I can barely remember my own lunch order half the time, let alone twelve separate secrets. Had a similar thing happen at a clinic where the head doctor thought keeping passwords on a sticky note under the keyboard was safer than any app. After a nurse "accidentally" left that same sticky note at the coffee station, we switched everything over to a manager and suddenly nobody was locked out or crying at their desk anymore. Some folks just gotta learn the hard way that memorizing stuff isn't the same as being secure. At least your old MSP boss probably never had to watch someone reset their password 14 times in one shift like I did.
3