this post was submitted on 15 May 2025
419 points (98.8% liked)

Games

39265 readers
1666 users here now

Welcome to the largest gaming community on Lemmy! Discussion for all kinds of games. Video games, tabletop games, card games etc.

Rules

1. Submissions have to be related to games

Video games, tabletop, or otherwise. Posts not related to games will be deleted.

This community is focused on games, of all kinds. Any news item or discussion should be related to gaming in some way.

2. No bigotry or harassment, be civil

No bigotry, hardline stance. Try not to get too heated when entering into a discussion or debate.

We are here to talk and discuss about one of our passions, not fight or be exposed to hate. Posts or responses that are hateful will be deleted to keep the atmosphere good. If repeatedly violated, not only will the comment be deleted but a ban will be handed out as well. We judge each case individually.

3. No excessive self-promotion

Try to keep it to 10% self-promotion / 90% other stuff in your post history.

This is to prevent people from posting for the sole purpose of promoting their own website or social media account.

4. Stay on-topic; no memes, funny videos, giveaways, reposts, or low-effort posts

This community is mostly for discussion and news. Remember to search for the thing you're submitting before posting to see if it's already been posted.

We want to keep the quality of posts high. Therefore, memes, funny videos, low-effort posts and reposts are not allowed. We prohibit giveaways because we cannot be sure that the person holding the giveaway will actually do what they promise.

5. Mark Spoilers and NSFW

Make sure to mark your stuff or it may be removed.

No one wants to be spoiled. Therefore, always mark spoilers. Similarly mark NSFW, in case anyone is browsing in a public space or at work.

6. No linking to piracy

Don't share it here, there are other places to find it. Discussion of piracy is fine.

We don't want us moderators or the admins of lemmy.world to get in trouble for linking to piracy. Therefore, any link to piracy will be removed. Discussion of it is of course allowed.

Authorized Regular Threads

Related communities

PM a mod to add your own

Video games

Generic

Help and suggestions

By platform

By type

By games

Language specific

founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] scops@reddthat.com 24 points 3 weeks ago (1 children)

I believe the main concern for periodic password changes is that most people won't take the time to generate unique passwords each time. They will typically iterate a password over time, meaning a couple leaked passwords will narrow down guesswork to a trivial number of guesses and remove the benefit of the timed changes.

NIST no longer recommends password expirations except for cases where it is believed that a breach occurred.

[–] JustAnotherKay@lemmy.world 18 points 3 weeks ago (1 children)

The other issue with periodic password changes, particularly in the workplace but also relevant in normal life, is that it causes people to write down their password. The issues with that should be glaring enough

[–] ripcord@lemmy.world 2 points 3 weeks ago (2 children)

What if they write it down in a single, centralizedz password manager? Which itself could be compromised?

That's the only way I can keep the literally 100 accounts ive accumulated over the years straight, without reusing passwords.

And while I believe that is reasonably secure in my case, if that got compromised I'd be pretty screwed (well, 2fa would probably still limit the worst of it). But most people probably wouldn't even be that secure about it.

Because it’s about reducing attack vectors, and your password manager isn’t likely going to be a vector. Attackers are going to try and net as many users as possible, which means (aside from heads of state or C-suite executives being spear phished) they aren’t targeting individuals… They’re targeting the companies that those individuals have accounts with. Essentially, you as an individual aren’t important enough to bother trying to hack individually. As long as your password manager has a sufficiently long password, (and you’re not one of the 1% of individuals who are rich or powerful enough to actually target), hackers won’t even bother trying.

With shared passwords, every single service you use is a potential attack vector; A breach on any of them becomes a breach on all of them, because they’re all using the same credentials. And breaches happen all the time, both because any single individual employee can be a potential weakness in the company’s security, (looking at the accountant who plugged a “lost and found” flash drive into their computer, and got the entire department hit with ransomware), and because the company is more likely to be targeted by attackers. With unique passwords and a manager, a breach on any service is only a breach on that service.

So by using a password manager, you essentially accept that breaches in individual companies are inevitable and out of your control, and work to minimize the damage that each one can do.

[–] GreyEyedGhost@lemmy.ca 1 points 3 weeks ago

I asked my company if I could use a password manager and they said no. So now they get a set of rotating passwords that are the same for all my work accounts. It doesn't really bother me - it's their data, not mine.