The Register Home Page

back to article BOFH: Deepfake or just an idiot? We'll need an audit to confirm

BOFH logo telephone with devil's horns "I... seem to have... uh, forgotten my password," the Boss burbles over the phone glumly. "I changed it the other day and I was pretty sure I put the new password in my password vault, only the password won't work." ">clickety< Did you try the reset password option?" I ask. "Yes. Yes, I …

  1. Anonymous Coward
    Anonymous Coward

    Round and round and round she goes. Each lap costs more money.

    One of my 2fa vaults is on a android device with a broken screen. If my still-working vault dies, I can either rebuild it from tokens stored in my password manager (unusable from the internet because of 3fa or usable because only 2fa from the LAN) or pay to get my tablet screen replaced.

    1. SVD_NL Silver badge

      That reminds me of my adventure of trying to recover 2FA codes (or stored passwords that hadn't synced for some reason) from my brother's phone, his LCD and his usb port were broken, but it was otherwise perfectly functional.

      I think i got a display and peripherals up and running through Samsung Dex (i first had to find a cable that worked, and hold it at a very specific angle with very specific pressure), but not all apps could be opened due to security restrictions (apparently screen recording restrictions apply to Dex). But i did a little workaround to enable wireless debugging, then got screen mirroring up and running from Android Studio, all that remained was trying to blindly find the fingerprint reader so he could open the password vault.

      I believe i also had to alternate between samsung dex and google cast because they both had certain apps that did and didn't open properly, just not sure what exactly i needed that for.

      Took me like half a day in total, roadblock after roadblock. I sent him an invoice as a joke, but he never responded!

    2. David Robinson 1

      I use FreeOTP+ on Android, as it allows you to export one or more of the keys. Any time I add a new 2FA, I export all the keys and store them in two separate secure locations.

      I also screen grab the QR codes to store in KeyPass2, as belt and braces, with different secure locations.

    3. FeRDNYC Bronze badge

      I had a similar experience a couple of years ago in a slightly lower-stakes (but still frustrating) context.

      I keep Messages on my phone paired to Google's Messages for Web client, because it means I can receive and send texts using my keyboard and mouse in a web browser, an infinitely more comfortable experience than thumbing messages in on my phone's soft keyboard. (And don't even get me started on the annoyance of finding photos or other media to attach, when it's anything other than the most recent shot taken with the phone camera.) Messages for Web is, honestly, the bee's knees.

      But because it's a web client gaining access to the inner workings of your Android device's privileged SMS client, a potential vector for anything from identity theft to exfiltration of all your most embarrassing secrets to out-and-out fraud and financial ruin, they keep the connection rather locked down. The pairing method is fairly robust (scan a QR code displayed by the web client using the phone you want to pair to), and web clients need to be re-paired fairly often, especially when they haven't been used in a while.

      At the time this came up, I was dealing with the fact that the rear camera on my phone had just bit the dust, a casualty of a swelling battery that popped it right off the back of the device and rendered it non-functional. Naturally, within 2-3 days of that happening, Messages for Web demanded that I re-pair my browser with the phone.

      Which involved scanning a QR code.

      Which is hard to do without a rear camera. (It wouldn't use the front camera, and it wouldn't accept an already-stored photo from device storage.)

      The punchline was, at the time (they've since fixed this), that method of pairing was the ONLY method of pairing available. Meaning, without a working camera on the device, I was locked out of Messages for Web completely, with my only recourse being to either get the phone's camera fixed, or buy a new phone with a working camera.

      I eventually did the latter, and Google eventually realized their system was being a pain in the ass by keeping itself a little too secure, so I guess ultimately the story has a happy ending? "Yay."

  2. DJV Silver badge

    Ahhh, bliss....

    There's nothing like the smell of a new BOFH early(-ish) on a Friday morning.

  3. Michael H.F. Wilkinson Silver badge
    Coffee/keyboard

    Superb episode

    Truly hilarious. The Boss neatly caught in a recursive catch-22-like situation

    1. Zürich Gnome

      Re: Superb episode

      catch-2fa?

  4. Hot Diggity

    Security as a service

    Service with a smile, that becomes more and more sincere the longer the phone call lasts.

    1. Pascal Monett Silver badge
      Devil

      Re: Security as a service

      An AI bot couldn't do as well. You need a true intelligence (albeit a devious one) to achieve such brilliance.

      1. b0llchit Silver badge
        Holmes

        Re: Security as a service

        Most victims will fall over when presented with a (picture of a) talking monkey and will send you anything you like. Using BOFH skills optimizes funds extraction.

  5. Anonymous Coward
    Anonymous Coward

    Very interesting.

    At the company I previously worked for (a defense contractor) were forbidden to use password vaults. The two factor authentication was using RSA tokens which I kept right next to my badge. Thankfully the password I used (they expire every 90 days) was a sequence and I noted the beginning of the sequence on my whiteboard. Not too useful unless you knew the sequence. Of course if needed lower case, upper case, digits, and a special. Thankfully I had them all!

    No circular round-robins for me!

    1. Kevin Johnston

      Re: Very interesting.

      Ah, sequential passwords. Every company I have been at tried to prevent those but none of them thought people might put the number at the start of the password

      1. Anonymous Coward
        Anonymous Coward

        Re: Very interesting.

        Dammit Kevin. Now they'll start thinking of it!

      2. Rich 11

        Re: Very interesting.

        My password has been 1password for the last 29 years.

        1. Anonymous Anti-ANC South African Coward

          Re: Very interesting.

          >clickety<>click<

          muhuhaha

      3. AlbertH

        Re: Very interesting.

        My "sequential" passwords were always easy to remember: Starting at the beginning of my professional career, I used the year and month and the city that I was working in at that time, Each new passsword was the next month.... and I worked in lots of different locations, all over the planet. It's easy enough to remember where I'm up to and I haven't ever got into the "forgotten password" loop....

        The system has proven flawless for many years - it just presupposes that you're as nomad an engineer as I am!

      4. herman Silver badge

        Re: Very interesting.

        I once was at password56 before the system changed again.

    2. SVD_NL Silver badge

      Re: Very interesting.

      I don't understand why some security teams keep insisting on very frequent password changes without a password vault. You just know people are going to re-use the same password and add a sequence, the more complex the requirements, the more likely they are to re-use (which may be predictable, e.g. if you find a password from a year ago that ends with 23, and you know the cycle is 90 days, the new password likely ends in 26)

      1. Anonymous Coward
        Anonymous Coward

        Re: Very interesting.

        Current NCSC advice is not to enforce regular password expiry.

        One of the reasons being "the user is likely to choose new passwords that are only minor variations of the old"

        1. Anonymous Coward
          Anonymous Coward

          Re: Very interesting.

          But when did anyone take those seriously....

          New company policy is actively suggesting "initial letters of words in a sentence"

          1. Dante Alighieri
            FAIL

            Re: Very interesting.

            so : ilowias for all.

          2. John Brown (no body) Silver badge

            Re: Very interesting.

            New company policy is actively suggesting "initial letters of words in a sentence"

            Which sounds like a reasonable way of creating an apparently random string of letters which can be quite long while still being memorable. Until you realise most people will use well known quotes, song lyrics, nursery rhymes etc and be a lot less random than hoped for.

            1. Donn Bly

              Re: Very interesting.

              TANSTAAFL

              1. the Jim bloke Silver badge

                Re: Very interesting.

                TANSTAAFOB

                (Onion Bhaji)

            2. the Jim bloke Silver badge

              Re: Very interesting.

              I used to like wobafgkmrns, but, as noted, it is an existing meaningful sequence.

              again, drawing from Larry Niven, Kplirapranthry, appropriate for gaining access to restricted whatever..

              both can be googled, and it whines about them being uncommon - which is good.

        2. Anonymous Coward Silver badge
          Thumb Up

          Re: Very interesting.

          It's either a predictable sequence, or going through the forgotten password process regularly.

          Thankfully every place I've worked I've managed to convince them that mandatory password expiration is a daft idea.

          1. Anonymous Coward
            Anonymous Coward

            Re: Very interesting.

            A college I periodically do some work for (and, consequently, have an email account with them - actually quite useful as it entitles me to educational discounts) has had a policy of monthly password changes for several years. They've just announced that they're dropping that in favour of a requirement for longer and more complex passwords. I haven't the heart to tell them I've not changed my password for their systems for at least 5 years (nor that it's already a long random sequence).

            1. parlei

              Re: Very interesting.

              One school I worked for did the 6 week password change routione[1]. Unless you changed your password just before going on vaccation it was expired and locked when you returned after summer...

              [1] The whole dance: number, special upper and lower, not resuse the last 17 passwords..

        3. gnasher729 Silver badge

          Re: Very interesting.

          Another reason not to require password changes: The user starts with a long, complicated password. When that needs changing they pick a shorter less secure password. About the fourth password will be useless.

          1. the Jim bloke Silver badge

            Re: Very interesting.

            Useless01, shirley..

            1. SVD_NL Silver badge

              Re: Very interesting.

              I'm not useless, and stop calling me Shirley!

        4. Pete Sdev Silver badge

          Re: Very interesting.

          Forcing regular password changes also drastically increases the likelihood of people keeping their current password on a post-it note on their desk.

          1. AlbertH

            Re: Very interesting.

            You've forgotten the "high security" version of the Post-It - the one that's taped to the underside of their keyboard or inside (or under) a desk drawer!

            1. M.V. Lipvig Silver badge

              Re: Very interesting.

              I just use a pattern, so muscle memory remembers my password. My password looks like someone threw up a bowl of alphabet soup unless you're looking at a QWERTY keyboard, in which case it looks like a couple of straight lines going in different directions. Come password change time, I just move the start character one button over.

            2. Spamolot

              Re: Very interesting.

              >You've forgotten the "high security" version of the Post-It - the one that's taped to the underside of their keyboard or inside (or under) a desk drawer!

              Gadzooks! You have passed level one of being a security audit specialist. For extra credits check the birthdays and names of immediate family and their pets. (You can safely ignore mother-in-laws and ex-s from your search unless prefixed/suffixed with DiE!die! DIE!)

        5. DS999 Silver badge

          Re: Very interesting.

          Current NCSC advice is not to enforce regular password expiry

          Wow they finally caught up to what I've been saying for 25 years!

          Even though I know I'm not supposed to I'd always use variations on my passwords in my consulting engagements, specifically to avoid the need to write stuff down. So if I started out with for example Password+1234 I'd do Password+2345 after 90 days and so on. I never had an engagement long enough to get past 7890 lol

          I incremented all four numbers because many systems will reject passwords with only one or two characters changing, but I never ran into one that rejected a 12 character password with 4 characters changing. This way the only thing I had to remember was an 8 character password that wasn't changing, plus my current start number for the last four. I'd always selected a new one for every client, but chosen in some way that would help me remember it and was also very fast to type to defeat shoulder surfers (the 1234 etc is also fast to type, so I could usually type all 12 characters so fast people couldn't even count how many characters it had let alone scope out my password)

        6. TeeCee Gold badge

          Re: Very interesting.

          Yes, I've always wondered at the logic in play there.

          If you do acquire someone's current password, does it really matter whether it's five minutes or five years old when it comes to what you can do with it? No, it does not.

          1. ExampleOne

            Re: Very interesting.

            The logic is that the password is a point in a suitably vast space. Exhaustively searching that space takes time, lots of time. Potentially years of time. Everytime you change your password, an attacker has to effectively restart their search in case your new password is in the already searched space.

            This assumes an attacker is carrying out a dumb exhaustive search, which in practice targeted attackers won't do. There comes a point where kidnapping you, drugging you, and beating you with a wrench until you tell them the password is cheaper than simply brute forcing it!

      2. John Robson Silver badge

        Re: Very interesting.

        And I don't understand the requirement for regular changes *with* a vault.

        Feel free to ping me a check if I log in from "somewhere new", or if there are failed login attempts (any)... but with a password generated by openssl... and backed by 2FA... what's the point in generating a different one?

        1. SVD_NL Silver badge

          Re: Very interesting.

          The main reason would be that someone could somehow get their hands on an (encrypted) dump of your password manager or the application's authentication database.

          If the passwords never change, you're giving this attacker a long time to work on cracking the passwords.

          Always assume encryption only slows down attackers.

          It won't apply to your aunt's Facebook login, but there are industries where attackers are willing to spend significant resources to get access.

          >"and backed by 2FA"

          I don't like this argument. Passwords matter when you use 2FA, thats the "2" part of it. If you don't secure your passwords, you're down to a single factor. Most places use TOTP for MFA too, what if the TOTP secret is stored in that file as well?

          1. John Robson Silver badge

            Re: Very interesting.

            There's a gap between never changes and cycling them every month.

            There is a reason this has to be combined with login source monitoring.

            1. The Oncoming Scorn Silver badge
              Pint

              Re: Very interesting.

              I use a band name, LP, year of release with special characters as my work password, the only variance at password renewal time is the point I hit the [SHIFT] key

              1. Sparkypatrick

                Re: Very interesting.

                RAtM-BoLA-1999?

          2. DS999 Silver badge

            Re: Very interesting.

            So if the attacker has two years to crack your password that's supposed to be a problem? Exactly who the hell would you have to be for someone to think it is worth devoting months let alone years of continuous cracking time to get your password? If you have a password that important, you will be using 2FA and who says you can only have one additional factor? Perhaps something that uber important justifies 3FA - a biometric scan plus a hardware key you keep on you at all times.

            1. John Brown (no body) Silver badge

              Re: Very interesting.

              Or, as our company does, has a password you never need to enter because entering the PIN is the first login option. Except the PIN has similar "complexity" requirements to the password. And both have to be changed every 90 days.

      3. BartyFartsLast Silver badge

        Re: Very interesting.

        We don't enforce regular password changes, our staff have several logon options including biometrics and the only time they need to change their passwords is when they get a new device because they're almost guaranteed to have forgotten their password.

      4. Anonymous Anti-ANC South African Coward

        Re: Very interesting.

        just use the names of random cities or countries...

        ...oops...

    3. Marty McFly Silver badge

      Re: Very interesting.

      Back in the day, I thought myself very clever to use two open square brackets in my passwords: [ and ]. When put together they form a box, which was the universal character used by some fonts when they cannot interpret the character code: []. I thought that would be a good way to fool anyone who randomly saw my password.

      As for sequential passwords... It is possible three digits in my password referred to the decade, year & quarter when that particular password change was required. Yes, other characters changed as well. But it made a good way to figure out which password to use when accessing a system I had not touched for a while.

    4. David Newall

      Re: Very interesting.

      Such complicated rules are no longer recommended by NSA as they inevitably lead to passwords on post-it notes, and thus lack any semblance of security the. The recommendation now is to use words. Just three English words gives 1.06E16 possibilities, assuming case is not important, and people find such passwords quite easy to remember.

      1. Anonymous Coward
        Anonymous Coward

        Re: Very interesting.

        "Just three English words gives 1.06E16 possibilities, assuming case is not important"

        I estimate that as three words of mean length of ~5⅓ random letters assuming no white space in the password.

        It's actually not that good as the order of letters in English are not random partly because they have some relationship if tenuous to phonetics. You also lose one letter for every letter 'q'.

        I vaguely recall the OED lists about 1 million words which would give 1.0E18 possiblities but with many of the words impractically long. The reasonably educated person's recognition vocabulary of words of practical length is probably around 100 thousand which would give about 1.0E15 possibilities which is roughly the 1.06E16.

        If the attacker could deduce the size of the account holder's recognition vocabulary they could reduce the search space. Manglement and C-suite would be prime targets given their evidently rather limited production vocabulary.

        Still Quell quaint quirks in practice is likely as decent a password as any; as doubtlessly would Fear feint ferrets

        I once, long ago, used a fairly short password beginning with a tab ('\t') on a Unix box. John the Ripper never got a whiff. :)

        1. John Brown (no body) Silver badge

          Re: Very interesting.

          Depending on the source study and how you define "vocabulary", it seems English speakers have a vocabulary of anything from 8000 to 30,000 words. I suspect the higher number is words people can recognise and maybe even define/understand, while the lower number is words people use in normal situations. Either way, it will cut the search area down significantly. And odds are, you can narrow it down even further when taking human nature into account, eg alliteration, rhyming, word-shapes etc. And even f people do use a "three words" type password, they'll probably all end with 1! to satisfy the banal complexity requirements.

          1. doublelayer Silver badge

            Re: Very interesting.

            Generally, the recommendation is to choose the words randomly, and not your brain randomly. I use that approach for temporary passwords given to others because it makes it easier to type, with the words selected from a list of about 25,000 words which should be recognizable to about everyone. I tend to use four and put hyphens between them to make them more distinct, which results in passwords like this:

            Predawn-Conferences-Ranting-Nice

            Milling-Thwarted-Plummeting-Accomplishments

            Beset-Typewriter-Vividly-Breezy

            Mathematically, these are about as random as a 9-character random password like j2#reXq"D which, on the surface, doesn't look great. They're a little better than the typical password though because people with a length limit like that won't choose their short password randomly either. Also, until an attacker knows that happens, it's much more secure because they're not limiting their search patterns. Still, if you need more entropy, you need it to be longer.

  6. steelpillow Silver badge
    Mushroom

    PayPal

    So horribly close to the truth.

    I don't have a mobile signal. PayPal offers an alt login. The alt login sends 2FA txt to my mobile... At the bottom of the login is an "If you can't log in, click here for help"

    Click for help. "To access help, please log in..."

    Grrr!...

    1. BobChip
      FAIL

      Re: Access help.......

      Way back in the 70s... If your phone stops working, just ring our help line from the number that has stopped working..... Seriously! They still live among us....

      1. John Robson Silver badge

        Re: Access help.......

        Keyboard not detected. Press F1 to continue.

        1. TG2.2

          Re: Access help.......

          Who in the hell downvoted you John?

          My guess is they don't understand sarcasm and secondary examples of it ...

          lol ... I mean I saw it and immediately chuckled .. would've possibly spit out a little coffee but thankfully cup is in need of a refill at the moment..

          1. John Robson Silver badge

            Re: Access help.......

            "Who in the hell downvoted you John?"

            Pretty sure there are a couple of people who actively hunt my posts in order to downvote them.

            I remember this bios message, and always thought it was ridiculous - but back in the day when keyboards weren't actually hotpluggable most of the time...

            1. John Brown (no body) Silver badge

              Re: Access help.......

              "I remember this bios message, and always thought it was ridiculous - but back in the day when keyboards weren't actually hotpluggable most of the time..."

              Yeah, it was the era of the PS/2 keyboard. Prior to that, the PC/XT/AT full size DIN plugs were mostly hot-pluggable and USB keyboards have been hot pluggable for most of their existence (some of the early ones were not always detected if plugged in after power on but before the OS boot was completed.)

              And IIRC, the error was mostly "Keyboard error, Press F1 to continue" with some variations from other manufactures/BIOS suppliers and mostly made sense except for the PS/2 keyboard era :-)

          2. steelpillow Silver badge
            Coffee/keyboard

            Re: Access help.......

            > Would've possibly spit out a little coffee

            What harm is there in that, if you have no keyboard?

        2. Spamolot

          Re: Access help.......

          This is probably up there with the old "Press any key to continue" and then you get a puzzled look as can't find that key...

      2. John Brown (no body) Silver badge

        Re: Access help.......

        "Way back in the 70s... If your phone stops working, just ring our help line from the number that has stopped working..... Seriously! They still live among us...."

        Virgin Media, still happening today (and probably most ISPs). Call them to report an internet fault and the first thing the recoded announcement suggests is to go to their online help pages. I suppose, in some respects, that is sort of sane since many will reach for the phone first for any and all "problems" and in this day and age, it's rare for people have an internet connection and not also have a smartphone capable of reaching said online help pages. But there was definitely a window of opportunity when that was not a given.

    2. DS999 Silver badge

      Re: PayPal

      Dunno if Paypal supports it but for some if you give it a "mobile number" that's actually a landline (I pay $6 a month for Ooma to keep my old landline number active at home, because it is a convenient number to give companies instead of my cell number) it will call instead of text and leave a voice message. I discovered that by accident but have used it other places just to avoid giving out my cell number and it works more often than not.

      Not sure how it determines the logic between calling and texting, it may only work for me since my number is on a prefix that existed long before cell phones so it might be treated differently. Or maybe it tries to send an SMS and it is getting an error kicked back by the PSTN. Dunno.

      1. G.Y.

        G voice Re: PayPal

        I give out my Google voice number in such contexts

      2. John Brown (no body) Silver badge

        Re: PayPal

        We had an elderly relative who had finally learned how to send text messages/SMS but still couldn't differentiate between our landline and mobile numbers in the phones directory. Her mobile operator (or our landline operator) seemed to be able to identify this "error" and we'd get an automated voice call that read out the text message and the source number.

  7. may_i Silver badge

    A valuable lesson

    This is a very good cautionary tale about how Scattered Spider and other groups who specialise in social engineering can be thwarted.

    An expensive lesson for The Boss and a great fund raiser for the BOFH's beer and curry fund!

  8. Anonymous Coward
    Anonymous Coward

    AC for obvious reasons. I know this experience only too well. I got a new phone a s a result of mine being destroyed in a house fire.

    I want to use Samsung security to store passwords, which means having my Samsung Account send a confirmation email to the email address used to set up the account.

    Unfortunately my Samsung Account was set up using my Google account which originally had an email address I haven't had access to for a few years because the friend whose mail server I was using died suddenly and no-one else had access to his servers.

    Because I used my Google account (which is now tied to my current email address), my Samsung Account doesn't have a password.

    So, I can't

    a) Access Samsung Security on my phone

    b) Change the email associated with my Samsung Account

    c) Add a password to my Samsung Account

    Because they all require a confirmation email being sent to my old email address.

    Apparently I can contact Samsung customer support to help me chnage the email address associated with my account, but they appear to only work during the hours I am at work

    1. may_i Silver badge

      Why on earth would you sign up for a Samsung account?

      If you'd done any research, you would know that the amount of data Samsung collects about you and what you do with your phone pales in comparison to what even Google collects!

      Sure, Samsung make nice hardware, but their thirst for data about their users to sell on to the highest bidder is insatiable.

      1. Hot Diggity

        My company-provided mobile is a Samsung. Every week or so it seems me a notification to agree to it's updated tend and conditions.

        As I don't trust Samsung in the slightest, I just discard the notification and everything continues as normal until the next notification.

        Samsung appear to have not thought of the possibility of someone not accepting the updated terms and conditions

        1. John Brown (no body) Silver badge

          The fact you get them every week or so seems to indicate that not accepting the new T&C generates a repeat message every couple of weeks. Since my Samsung is a work provided phone, I just accept them when they come once or twice per year. I did ignore it the first time it happened, and also got "new" messages every few weeks until I did accept.

      2. doublelayer Silver badge

        I recently learned on someone else's phone that Samsung no longer lets you update any of the builtin apps without one. Before, if you wanted an update, you could go to the Galaxy Store entry for the app and update it, and at one time, you could even install things, but now, both of those are gated by a login. Which makes me feel less pleasantly toward Samsung, but that might be one reason people set up such an account.

    2. John Brown (no body) Silver badge

      "Apparently I can contact Samsung customer support to help me chnage the email address associated with my account, but they appear to only work during the hours I am at work"

      Don't you get lunch break? Or is the phone queue longer than that?

    3. Anonymous Anti-ANC South African Coward

      Sagsmug.

  9. Prst. V.Jeltz Silver badge
    Flame

    TOTP auth

    One of our suppliers has added TOTP authentication to the login used for setting up m2m access .

    It will work when you first set it up . It *might* work six months later .

    It sure as hell wont work if you attempt to move the original seed string to a new auth app .

    They appear to know nothing about how their own 2FA works and their solution to when it stops working it to "DELETE your account and start again re certifying all the certificates"

    Luckily the only time i log in is when certs need renewing anyway , but pretty much every time the TOTP fails and this circus goes round again .

    1. Throatwarbler Mangrove Silver badge
      Joke

      Re: TOTP auth

      Surely, as a Vogon, you have some appreciation for this technique ...

    2. David Newall

      Re: TOTP auth

      Why would that be?

  10. Throatwarbler Mangrove Silver badge
    Unhappy

    Similar

    I was helping my father set up a new phone because he'd lost his old one. Being an Android, it wanted his Google account information and tried to send a 2FA notification to his old phone. Fortunately, I had his login credentials and was able to disable or redirect MFA, but it was touch and go for a bit.

    1. M.V. Lipvig Silver badge

      Re: Similar

      Interesting - I always use a new account when I get a new phone. I don't use it for anything beyond setting up the new phone, and I keep nothing of importance on my phone anyway.

  11. TG2.2

    Stupidity Extreme ..

    This is one of the reasons I prefer Google Auth .. not that DUO can't .. but many companies seem to think having your duo account on multiple devices that you keep with you at all times is a security issue/risk not worth taking.

    But with GAuth, its automatically backed up, device breaks? get new device, restore GAuth and bobs yer uncle.

    leave your phone in your car (recently new car with Android Auto and I plug in for that) and you're not immediately in distress walking down 3 floors to get it, and then back up again (I'm older doing such a thing twice in one day is like asking for a sweat shower or near cardiac infarction)

    On top of that .. we use Zoom for phone services (not my choice) and you can set that as the Cellular number to send texts to for that last hope auth method .. and well at least they appear to allow two of the same type of logins (eg 2pc, 2mobile) by default with the company having the ability to allow more (but ours doesn't .. again 'tupid) so even there ... its more fault tolerant with all things equal.

    I've been in circular situations with clients, who registered a domain .. set the admin email, tech, abuse, etc .. all to be email addresses that are within the same domain .. and I've seen the 3 days it takes to recover said domain with faxes of documents proving ownership to get them back to active again because some yotz ignored or thought it spam or phishing or their email filtering did, and they never saw the expiry notices, nor had a calendar set to remind them ..

    It took my previous company (an MSP) 4 years to finally get on board with tracking EVERY client domain vs getting the angry client "my mails not working" and me being senior every time doing the first check to see expired domains .. they added the expiry dates into ITGlue (their relatively new note keeping) and they could've just created a scheduled ticket in their own ticketing system ..

    ... but regardless ... looking out for such looping and process failure has become so ingrained into my tech being I feel pain when/if I miss something .. lol

    Anyway .. fun BOFH

  12. earl grey

    so, is 123456 still ok to use

    Been through the security wringer more times than i want to think about, so this is actually funny in more ways than one.

  13. JessicaRabbit Silver badge

    Another excellent tale of user management done right.

  14. Anonymous IV
    Unhappy

    It follows...

    It looks like the Boss has discovered that 2FA is Sweet FA...!

  15. Blackjack Silver badge

    Hey remember when some computers had actual real locks with keys? Maybe we should go back to that

    1. Anonymous Anti-ANC South African Coward

      A doddle to override these if you know how.

      Most new motherboards doesn't have the required pins for a keyboard lock.

      1. doublelayer Silver badge

        It depends what the lock is supposed to lock. If it's supposed to prevent the computer from running anything at all, then it would need a case that's effectively a safe so you can't just open it up and disconnect it. But you could prevent it from booting without a separate device by encrypting the disk and requiring the additional device to provide the keys needed to decrypt it, and a BIOS patch could make that device unclonable by doing a key exchange when first set up and always communicating with that encryption and random challenges afterward. There are a few places you could lock without needing to harden the computer too much.

  16. agurney

    my sequence is the registrations for vehicles that I've owned over the past 50 years; easy to remember for me, and If a password hint was required "blue cortina" or "red mini" wouldn't help anyone else. Latterly had to append a phrase to meet minimum length + special characters.

    1. Potty Professor
      Boffin

      Password reminder

      I also use my past registration marks as passwords, but with the addition of various spaces/dashes/underlines to satisfy the requirements for symbols.

      I caught a cold with this recently when I was unceremoniously moved from BT to EE and they sent me a new router. The old BT router accepted spaces in the password, but the EE router didn't, so I had to revisit every device connected to it and change all the spaces to minuses. Not exactly a difficult task, but one I could have done without, and why the difference anyway?

      I do not use my Cherished Registration Mark, that has not changed since I acquired it attached to an old banger in 1974, and is now on a Retention Certificate as it is worth loadsa money.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like