<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Enterprise Security on Chris Worth</title><link>https://chrisworth.dev/skill-tag/enterprise-security/</link><description>Recent content in Enterprise Security on Chris Worth</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 11 Mar 2025 09:00:00 -0600</lastBuildDate><atom:link href="https://chrisworth.dev/skill-tag/enterprise-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Modern Password Security: Why Everything You Were Taught Is Wrong</title><link>https://chrisworth.dev/posts/enterprise-password-security-best-practices/</link><pubDate>Tue, 11 Mar 2025 09:00:00 -0600</pubDate><guid>https://chrisworth.dev/posts/enterprise-password-security-best-practices/</guid><description>&lt;p>I spent years following password rules that made security worse. Change passwords every 90 days, use uppercase, lowercase, numbers, and symbols, never reuse passwords. Under those rules, &amp;ldquo;Spring2025!&amp;rdquo; rotating to &amp;ldquo;Summer2025!&amp;rdquo; rotating to &amp;ldquo;Fall2025!&amp;rdquo; is fully compliant, and that&amp;rsquo;s exactly the problem: the rules select for compliance, not for unpredictability.&lt;/p>
&lt;p>I checked passwords built that way against breach databases anyway, out of habit more than doubt. Every single one appeared in credential dumps available to anyone willing to look. The rules designed to protect me were training me to be predictable.&lt;/p></description></item></channel></rss>