• Apathy Tree@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    6
    ·
    2 hours ago

    I used to work at a company that processed business-end taxes.

    I’m going to make my American compatriots very uncomfortable - I’ve very possibly seen your full social and address info. We handled about a third of all business taxes. I don’t care to use any of it, cuz I also got wage info. Y’all broke. (Same)

    because the company I worked for processed your taxes. And your HR people are garbage and don’t know how to do their job.

    I cannot tell you how many times I had to request my IT team to scrub files from our retention policy because your shitty HR sent it to me in cleartext to troubleshoot instead of through our encrypted box.

      • AceOnTrack@lemmy.blahaj.zone
        link
        fedilink
        arrow-up
        3
        ·
        44 minutes ago

        People aren’t lazy, we just don’t give a shit about cybersecurity, it’s not as big of a deal as IT makes it.

        I use an Excel worksheet for my passwords.

        At my workplace, I need to use a dozen different webapps/VMs, some of them only like once every 2 months.

        For some reason, each fucking app requires different password combinations with different rules, and their all have different password change times.

        I ain’t remembering all that.

        I used to keep a notepad with all my passwords in my desk drawer but I occasionally remote login on my machine nowadays, so I have a passwords.xls file on my desk. It’s even got some formulas that warns me when one is about to expire and needs to be changed, I put some effort into it.

    • Prox@lemmy.world
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      3 hours ago

      The kind of savage whose company is too cheap for a LastPass enterprise license?

  • funkless_eck@sh.itjust.works
    link
    fedilink
    arrow-up
    2
    ·
    1 hour ago

    you don’t really need to hack the excel sheet, most corporate passwords are the name of the company with a 3 replacing the e and an exclamation mark

      • vrek@programming.dev
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 hours ago

        I knew a senior engineer who did this. Granted I don’t blame him, elevated accounts (basically admin accounts) had corporate assigned 36 character(letter, number and special) randomly generated passwords which expired every 6 hours. If you used the account on more than 3 computers the password expires.

        To get new password you had to log in with normal account, go to special website, log in with your account and a authenticator code from company phone, request new password, write in a reason why you need it, go back to homepage of special website, approve your own request, go to your manager, ask them to approve it also, go back to special website, likely need to relogin including authenticator, finally new password is shown on screen for 30 seconds…