• 2 Posts
  • 49 Comments
Joined 1 year ago
cake
Cake day: July 12th, 2023

help-circle







  • The current thinking as I understand it is expiry policies make most types of accounts less secure because users just cycle through the same predictable pattern of adding increasing numbers of exclamation points or incrementing the last digit at each required password change, and if you require new passwords to be too substantially dissimilar from x number of previous ones then users can’t remember them at all. Policies that make people use minimally complex passwords because they have too many to remember and don’t understand how password managers work inevitably increase password reuse between services and devices which does the opposite of improving security. Especially with MFA enforced, which I’ve been known to do as aggressively as I can get away with, there’s just no sense in requiring regular password resets – as long as the password remains complex, unique, and uncompromised. I’m not a network security expert but I am responsible for managing these sorts of things in my role and that’s the rationale I use for the group policies in a typical customer’s environment.














  • Second the NUC suggestion. I’ve got a 10th gen i7 model that I use primarily as a media server. It draws <6W at idle so it runs 24/7 and barely makes a blip on my electricity bill. It’s been rebooted exactly twice so far this year after switching from Windows 10 to Arch (BTW), once after a planned upgrade and a second time unexpectedly when my cheap UPS’s battery died. It works fine with the two docking stations I’ve tried and two different USB-C displays. I think my model might need a small adapter to support a third monitor but I’m not sure that’s the case with newer generations, though you may have to look beyond the Intel-branded hardware if you do want a more recent edition since they sold the brand to ASUS.