Quote:
Originally Posted by jammies
An IT department that thinks 30 character passwords are secure is an IT department that either is incompetent or is being forced by upper management to do stupid things to make it look like security is "improving".
|
In our case, it's demands from clients - "you must meet these specific security standards as a pre-requisite to us working with you", etc. Everyone in IT knows the requirements are dumb, but they have no real choice.