Elektrine lite

← Feed

@nyanbinary@infosec.exchange

2026-09-23 15:18 UTC

central-european-levels-of-spicy take: I do actually think credentials should have a defined lifetime limit & (in a somewhat professional context) this should be enforced. This applies to the full spectrum of machine to human credentials, with potentially the exception of specific machine credentials with strong technical & process controls & with appropriate frequencies to each credential type. Don't read this as me wanting to return to the days of "30 day password rotation :neodog_gun: " but it's actually fine and good if passwords naturally age out. A percentage of your employees personal laptop will, for stupid reasons that made sense at the time, will somewhere include their corporate password from 3 years ago. A percentage of your developers will somehow for some reason have granted themselves access with personal devices to corporate infrastructure 2 years ago and forgot to revoke that. Your VP Sales may have learned a bit more about password reuse & patterning in the last 6 years & may apply this to new passwords. No matter how good your EDR is, you do not have visibility into this. Identity CTI & password audits are limited in what they can detect. Your Conditional Access & device binding will have gaps. Just make sure stuff gets rotated once in a CEOs tenure or whatever arbitrary but sufficiently long time period, this WILL close gaps.

Replies (1)