I used to work at a company that processed business-end taxes.
I’m going to make my American compatriots very uncomfortable - I've very possibly seen your full social and address info. We handled about a third of all business taxes. I don’t care to use any of it, cuz I also got wage info. Y’all broke. (Same)
because the company I worked for processed your taxes. And your HR people are garbage and don't know how to do their job.
I cannot tell you how many times I had to request my IT team to scrub files from our retention policy because your shitty HR sent it to me in cleartext to troubleshoot instead of through our encrypted box.
Well my company HR was so dumb I used to be able to look up everyone's personal information and income because they tried using Salesforce to store employee data but didn't know how permissions worked.
As one of the lower paid employees according to that info. It was not my problem. I don't work in IT and didn't get hired for my technical experience, so I offer none.
People aren't lazy, we just don't give a shit about cybersecurity, it's not as big of a deal as IT makes it.
I use an Excel worksheet for my passwords.
At my workplace, I need to use a dozen different webapps/VMs, some of them only like once every 2 months.
For some reason, each fucking app requires different password combinations with different rules, and their all have different password change times.
I ain't remembering all that.
I used to keep a notepad with all my passwords in my desk drawer but I occasionally remote login on my machine nowadays, so I have a passwords.xls file on my desk. It's even got some formulas that warns me when one is about to expire and needs to be changed, I put some effort into it.
And I'm sure the person who steals that file will really appreciate the effort you put in.
I've literally searched networks for files with the word "password" in the title to find documents just... sitting on a network drive anyone could access.
At the very least, go get KeePass! It's free, can run without installation, and can even type for you.
I knew a senior engineer who did this. Granted I don't blame him, elevated accounts (basically admin accounts) had corporate assigned 36 character(letter, number and special) randomly generated passwords which expired every 6 hours. If you used the account on more than 3 computers the password expires.
To get new password you had to log in with normal account, go to special website, log in with your account and a authenticator code from company phone, request new password, write in a reason why you need it, go back to homepage of special website, approve your own request, go to your manager, ask them to approve it also, go back to special website, likely need to relogin including authenticator, finally new password is shown on screen for 30 seconds....
22 replies
Be like me and use notepad!
Notepad++ inside an encrypted container.
I used to work at a company that processed business-end taxes.
I’m going to make my American compatriots very uncomfortable - I've very possibly seen your full social and address info. We handled about a third of all business taxes. I don’t care to use any of it, cuz I also got wage info. Y’all broke. (Same)
because the company I worked for processed your taxes. And your HR people are garbage and don't know how to do their job.
I cannot tell you how many times I had to request my IT team to scrub files from our retention policy because your shitty HR sent it to me in cleartext to troubleshoot instead of through our encrypted box.
Well my company HR was so dumb I used to be able to look up everyone's personal information and income because they tried using Salesforce to store employee data but didn't know how permissions worked.
As one of the lower paid employees according to that info. It was not my problem. I don't work in IT and didn't get hired for my technical experience, so I offer none.
What kind of fucking savage uses Excel as a password manager?
It’s ok, it’s only on the hr lady’s computer and she always locks the door
The publicly traded company I recently worked for did. You'd be surprised, people are lazy.
People aren't lazy, we just don't give a shit about cybersecurity, it's not as big of a deal as IT makes it.
I use an Excel worksheet for my passwords.
At my workplace, I need to use a dozen different webapps/VMs, some of them only like once every 2 months.
For some reason, each fucking app requires different password combinations with different rules, and their all have different password change times.
I ain't remembering all that.
I used to keep a notepad with all my passwords in my desk drawer but I occasionally remote login on my machine nowadays, so I have a passwords.xls file on my desk. It's even got some formulas that warns me when one is about to expire and needs to be changed, I put some effort into it.
And I'm sure the person who steals that file will really appreciate the effort you put in.
I've literally searched networks for files with the word "password" in the title to find documents just... sitting on a network drive anyone could access.
At the very least, go get KeePass! It's free, can run without installation, and can even type for you.
savages?
real men use a plain text fill named notmypasswords to throw off hackers
You would be appalled to deal with c-suites
The kind of savage whose company is too cheap for a LastPass enterprise license?
I used to trust last pass but with all their security breaches in the past few years...
Mine just uses Keepass.
My wife.
Next you will tell me they are using Excel as a database.
you don't really need to hack the excel sheet, most corporate passwords are the name of the company with a 3 replacing the e and an exclamation mark
Everyone knows the best password manager is notepad!
Pleb. Notepad+
I knew a senior engineer who did this. Granted I don't blame him, elevated accounts (basically admin accounts) had corporate assigned 36 character(letter, number and special) randomly generated passwords which expired every 6 hours. If you used the account on more than 3 computers the password expires.
To get new password you had to log in with normal account, go to special website, log in with your account and a authenticator code from company phone, request new password, write in a reason why you need it, go back to homepage of special website, approve your own request, go to your manager, ask them to approve it also, go back to special website, likely need to relogin including authenticator, finally new password is shown on screen for 30 seconds....
You want me to store my passwords on servers owned by like Amazon?
Is this gatekeeping?