Announcement

Collapse
No announcement yet.

Security through obscurity

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Security through obscurity

    I just spent 20 minutes trying to change my password on my company's HR site.

    Passwords expire after 90 days, regardless of how often you log in. To reset a password, the system asks for the 'old' password...which is expired, so the system throws a generic 'invalid credentials' error. WTF.

    No clear information in the error message as to what the problem is (I had to google the error number and figure a workaround based on what the IBM helpsite said). The helpdesk phone # on the site is invalid; I called the number only to get a message that the number had changed, the new number gave me a "This call cannot be completed" message.

    I had to create a new password using the 'new user' link, only then would it let me select a new one (entering that password resulted in the 'password expired, please change password' screen, but since the 'new' one was in the system I was allowed to change it).

    So if a password is expired, in order to change it you need to create a new password (you need a password to change the password), back in and then change it again. Of course, the end user doesn't get to know that. At least my bank lets you know that a password is expired and gives a valid phone # to reset it.
    Last edited by Dreamstalker; 07-24-2012, 02:21 PM.
    "I am quite confident that I do exist."
    "Excuse me, I'm making perfect sense. You're just not keeping up." The Doctor
Working...
X