|
|
|
|
|
by ornornor
27 days ago
|
|
I worked some (terrible) place that did that and wouldn’t allow you to use your last 3 passwords. So what we were doing is that when it was time to rotate password, we would change our password 3 times in a row and on the fourth time we would just use the same password as before. This way our password never changed (the requirements for passwords were ridiculous) and the box could be checked in the audit. Also the same company: we ran a version of our artifact repository that had a 10.0 CVE for almost a year. It was too much work to update it, couldn’t spare the resources. |
|