zlacker

[return to "I read the federal government’s Zero-Trust Memo so you don’t have to"]
1. pagane+PF[view] [source] 2022-01-27 18:16:24
>>EthanH+(OP)
> Do not give long-lived credentials to your users.

This screams "we'll use more post-it notes for our passwords compared to before", or maybe the real world to which this memo is addressed is different compared to the real (work-related) world I know.

◧◩
2. the_je+7L[view] [source] 2022-01-27 18:39:20
>>pagane+PF
It specifically calls out not requiring regular password rotation. Short-lived credentials is for tokens with expiration, not the password you use to login to the service that gives you the token.
[go to top]