Yeah but a secure password changed regularly should be secure.True, but 2FA is so much more secure. Not having it really leaves you open to various types of attacks.
Yeah but a secure password changed regularly should be secure.True, but 2FA is so much more secure. Not having it really leaves you open to various types of attacks.
Yeah but a secure password changed regularly should be secure.
Yeah but a secure password changed regularly should be secure.
Your password is something you know, while 2FA is something (a device, usually) you have as well as something you know.
Sorry, should have emphasised the "as well as" in my response. Yes, you need bothThe key being that it's both of these things. If it's just something you have, if your phone gets nicked then people can get into everything. This has happened by way of SMS 1FA* by putting the SIM card in another unlocked device, for instance. (This is one way in which eSIMs are superior to physical ones - you can't!)
* i.e. just the phone bit, no password alongside it.

My employer's head of security dislikes app based 2FA. He is however a fan of physical token based MFA.Yes, Microsoft's authenticator app is now thankfully becoming a standard across a lot of organisations. Aegis Authenticator is a good open source alternative, too.
The aforementioned head of security believes the best password is one you don't know, using a password manager to store all your passwords which should be of a complex nature, and believes that having passwords that require changing every x days is of no security benefit.Yeah but a secure password changed regularly should be secure.
My employer's head of security dislikes app based 2FA. He is however a fan of physical token based MFA.
That’s not quite accurate. There has been a recent push around phishing resistant MFA. App based authentication using methods such as OTP still have weaknesses. Whereas if the hardware token is something like a Yubikey then it has a fingerprint reader.So he's about as competent as people who think Apple/Google Pay is less secure than physical contactless payment cards, then. That is, he isn't competent at all!
Clue: in both cases there is no authentication to get the code/make a payment with a physical token/card, but there is with a phone!
Whereas if the hardware token is something like a Yubikey then it has a fingerprint reader.
Out of interest what’s the reason not to reuse?Well if you want to reduce and reuse then fill a bottle from the tap and don't buy the single-use bottles at all. The single use PET bottles are not designed for reuse and can lead to other issues if reused.
The main reason is they are hard to clean and also when they get old and crinkle that makes crevices bacteria can remain in. There may also be a risk of plastic breakdown.Out of interest what’s the reason not to reuse?
I regularly re use the plastic bottles of water you get given for free on board train first class
Should I not be doing so?
It wasn't a chain as far as I'm aware. Maybe part of a small chain if so!Not part of the Britannia group by any chance?
Thanks. Helpful info.The main reason is they are hard to clean and also when they get old and crinkle that makes crevices bacteria can remain in. There may also be a risk of plastic breakdown.
Generally using 2-3 times is fine, but if you need to reuse it a lot then get a bottle designed to be reused and washed.
Why are you preaching to me, when you replied to my previous comment in which I wrote "For water I try to remember my water bottle". Or did you not read the entire very very short comment and rushed to make a haughty quip ?Well if you want to reduce and reuse then fill a bottle from the tap and don't buy the single-use bottles at all. The single use PET bottles are not designed for reuse and can lead to other issues if reused.
The highest end yubikeys have fingerprint readers, but the bulk of them just have a touch sensor (which can be used to confirm that someone - but not necessarily the right person - is physically present before the key can authenticate)That’s not quite accurate. There has been a recent push around phishing resistant MFA. App based authentication using methods such as OTP still have weaknesses. Whereas if the hardware token is something like a Yubikey then it has a fingerprint reader.
There was no intention to make a “haughty quip”, I was just replying to the flippant statement “I see. Well.... another fine example of pretending the first two 'R's don't exist. As long as we recycle recycle recycle, that's three Rs!” where you were implying you are only interested in the reuse of single use bottles. This follow up where you now state you try to remember your own water bottle answers your own comment, the first two R of reduce and reuse do exist when you remember to.Why are you preaching to me, when you replied to my previous comment in which I wrote "For water I try to remember my water bottle". Or did you not read the entire very very short comment and rushed to make a haughty quip ?
Yep I don’t know my passwords but funnily enough quickly memorised my Xbox Microsoft password as I typed it in every time I signed in. But it was also shortened as I heard old x360 accounts can only accept shorter passwords. It’s an apple keychain type password so it made me question how easy it hard it is to really memorise them. The main reason we don’t memorise them is because we don’t have to type them in. But I guess also because we can have so many passwords.My employer's head of security dislikes app based 2FA. He is however a fan of physical token based MFA.
The aforementioned head of security believes the best password is one you don't know, using a password manager to store all your passwords which should be of a complex nature, and believes that having passwords that require changing every x days is of no security benefit.
I agree with the bloke on some of this but not all.
Apple/Google pay are more secure although I heard with visa you can hack Apple Pay express checkout if you know how to.So he's about as competent as people who think Apple/Google Pay is less secure than physical contactless payment cards, then. That is, he isn't competent at all!
Clue: in both cases there is no authentication to get the code/make a payment with a physical token/card, but there is with a phone!
Yes, the Nottingham one is particularly disgusting. But I've had a few decent stays at places like Bosworth Hall, Buxton Palace Hotel and the Royal Bath in Coventry. All tired, but for the price they're not bad.It wasn't a chain as far as I'm aware. Maybe part of a small chain if so!
I have stayed at a Britannia in Nottingham and never again. I think the Home Office eventually forced them to take photocopies of all guest IDs, even British citizens, as there was so much people trafficking and sex trafficking going on. The hotel itself was filthy. I think I'd rather stay in a university dorm room for the night instead!
In an ideal world, perhaps.Yeah but a secure password changed regularly should be secure.
Regular password expiry is a common requirement in many security policies. However, in the Password Guidance published in 2015, we explicitly advised against it. This article explains why we made this (for many) unexpected recommendation, and why we think it’s the right way forward.
Let’s consider how we might limit the harm that comes from an attacker who knows a user’s password. The obvious answer is to make the compromised password useless by forcing the legitimate user to replace it with a new one that the attacker doesn’t know. This advice seems straightforward enough.
The problem is that this doesn’t take into account the inconvenience to users - the ‘usability costs’ - of forcing users to frequently change their passwords. The majority of password policies force us to use passwords that we find hard to remember. Our passwords have to be as long as possible and as ‘random’ as possible. And while we can manage this for a handful of passwords, we can’t do this for the dozens of passwords we now use in our online lives.
To make matters worse, most password policies insist that we have to keep changing them. And when forced to change one, the chances are that the new password will be similar to the old one.
Attackers can exploit this weakness.
The new password may have been used elsewhere, and attackers can exploit this too. The new password is also more likely to be written down, which represents another vulnerability. New passwords are also more likely to be forgotten, and this carries the productivity costs of users being locked out of their accounts, and service desks having to reset passwords.
It’s one of those counter-intuitive security scenarios; the more often users are forced to change passwords, the greater the overall vulnerability to attack. What appeared to be a perfectly sensible, long-established piece of advice doesn’t, it turns out, stand up to a rigorous, whole-system analysis.
The NCSC now recommend organisations do not force regular password expiry. We believe this reduces the vulnerabilities associated with regularly expiring passwords (described above) while doing little to increase the risk of long-term password exploitation. Attackers can often work out the new password, if they have the old one. And users, forced to change another password, will often choose a ‘weaker’ one that they won’t forget.
Yeah I don't mind as long as places are clean. Depending why I'm staying in the hotel, I'm often quite happy to accept a dated interior and a tiny TV in exchange for a lower price.Yes, the Nottingham one is particularly disgusting. But I've had a few decent stays at places like Bosworth Hall, Buxton Palace Hotel and the Royal Bath in Coventry. All tired, but for the price they're not bad.
The aforementioned head of security believes the best password is one you don't know, using a password manager to store all your passwords which should be of a complex nature, and believes that having passwords that require changing every x days is of no security benefit.
I agree with the bloke on some of this but not all.
I thought the Nottingham Britannia was wholly leased to the Home Office at the moment for asylum seeker accommodation.Yes, the Nottingham one is particularly disgusting. But I've had a few decent stays at places like Bosworth Hall, Buxton Palace Hotel and the Royal Bath in Coventry. All tired, but for the price they're not bad.
Yeah I don't mind as long as places are clean. Depending why I'm staying in the hotel, I'm often quite happy to accept a dated interior and a tiny TV in exchange for a lower price.
I thought the Nottingham Britannia was wholly leased to the Home Office at the moment for asylum seeker accommodation.
It was once a pretty smart hotel - certainly c 10 to 15 years ago when I think I was in there - if from the late 1960s / early 70s concrete block style of architecture.
There's a Travelodge I've stayed at for Christmas a week at a time, a few times over the past few years. It is around half the price of any other hotel around, and perfectly clean. The rooms are very basic, but to be honest I come back to the room from spending a day with the family, go straight to sleep, wake up, shower, take dog for walk, and head back over to see the family again. Don't really bother with the TV or WiFi and there's breakfast options nearby if I wanted to buy something.Problem is the cheaper end almost always compromise on cleanliness. The only time you ever get a tiny basic room but with a good (single) bed, no or a 14" TV etc but spotless and everything working is a family owned hotel. Travelodge for instance always seem to be dirty and in poor repair.
Problem is the cheaper end almost always compromise on cleanliness. The only time you ever get a tiny basic room but with a good (single) bed, no or a 14" TV etc but spotless and everything working is a family owned hotel. Travelodge for instance always seem to be dirty and in poor repair.
I thought the Nottingham Britannia was wholly leased to the Home Office at the moment for asylum seeker accommodation.
It was once a pretty smart hotel - certainly c 10 to 15 years ago when I think I was in there - if from the late 1960s / early 70s concrete block style of architecture.
Travelodge is SO hit and miss, I've stayed at some dated ones that were clearly well cared for (Saltash) but there are lots that are dated and unclean. The Britannia hotels I've stayed at have had clean rooms, but the rest of the property outside of the reception / ball rooms is often starved for maintenance - but then as the properties are SO big I can see why it takes so long to update everything.
Probably also a realisation that with multiple systems requiring phenomenally long and meaningless passwords all changing at different times and different intervals people end up writing them down, which rather defeats the object.The problem of course being that most people don't use a secure password.
The wisdom of changing it is, er, changing a bit. My current employer doesn't require that we change them at all. I believe there's now a reckoning that as long as you use enough bits of entropy (i.e. a long password, e.g. a sentence rather than a word) the only need to change it is if you think it may have been breached by way of social engineering, as a brute force attack on a very long password is near impossible.
Interestingly, a lot of security people have actually swung the other way on having 'password books.' As most attacks now are virtual rather than physically present attacks like the past having an offline password book stored in a locked drawer is actually not as unsafe as it used to be...Probably also a realisation that with multiple systems requiring phenomenally long and meaningless passwords all changing at different times and different intervals people end up writing them down, which rather defeats the object.
Interestingly, a lot of security people have actually swung the other way on having 'password books.' As most attacks now are virtual rather than physically present attacks like the past having an offline password book stored in a locked drawer is actually not as unsafe as it used to be...
It's definitely more preferable than just having the same password for every site.
There's a Travelodge I've stayed at for Christmas a week at a time, a few times over the past few years. It is around half the price of any other hotel around, and perfectly clean. The rooms are very basic, but to be honest I come back to the room from spending a day with the family, go straight to sleep, wake up, shower, take dog for walk, and head back over to see the family again. Don't really bother with the TV or WiFi and there's breakfast options nearby if I wanted to buy something.
Travelodge is SO hit and miss, I've stayed at some dated ones that were clearly well cared for (Saltash) but there are lots that are dated and unclean.