….and the most scarce is common sense….
Rick.
--
You received this message because you are subscribed to the Google Groups "ntsysadmin" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
ntsysadmin+...@googlegroups.com.
To view this discussion visit
https://groups.google.com/d/msgid/ntsysadmin/CADy1Ce63Bie0V2oCbVQJzVeVn_fdf3Tb42vjqboRGgH0XVn3ew%40mail.gmail.com.
We had a partner have their accounts and lines of credit drained.
Me: Do you use the same password everywhere?
Them: Yes
Me: Did you enable the bank’s challenge questions (at that time before app 2FA)
Them: No
Me: Did you change the password?
Them: Yes
Me: Is it completely different?
Them: Um, not really
Me: Here’s KeePass let me train you on it.
Them: Okay
A couple months later, I asked them if they were updating all of their web site passwords using the KeePass generator and enabling 2FA across the board.
Nope.
The bank refunded their accounts though. I’m not sure that’s the prescription for fixing the PEBKAC issue.
Philip Elder MCTS
Senior Technical Architect
Microsoft High Availability MVP
MPECS Inc.
E-mail: Phili...@mpecsinc.ca
Phone: +1 (780) 458-2028
Web: www.mpecsinc.com
Blog: blog.mpecsinc.com
Twitter: Twitter.com/MPECSInc
Teams: Phili...@MPECSInc.Cloud
Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Kurt Buff
Sent: Wednesday, December 3, 2025 11:43
To: ntsys...@googlegroups.com
Subject: [ntsysadmin] LOL - and yet tears of sadness and rage
It's hard not to be cynical anymore
--
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/ABCEB02DCBBDBB429FE098A2F85D11DA09BBEE18%40VENUS2A.RMC-CORP.local.
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/a38de909a5b347488f9a55b047f923de%40MPECSInc.Ca.
PEBKAC, sure, but here’s the thing: People have a lot of accounts.
We have people in direct care who have a half-dozen accounts that presumably should have a half-dozen passwords, all of them suitably long and/or complex.
Then they have personal accounts. This morning, I downloaded to my phone the remote app for a TV (it doesn’t have a physical remote). It required me to sign on with an account. Why do I need an account to change channels or volume? Don’t know.
Anyway, I can tell people: Use password keeper. They say, OK, and sign up for Lastpass (or whatever). When that gets compromised, then what do I tell them?
I’m just saying that passwords are a problem, no matter what people do.
--
John Wright
IT Support Specialist
![]()
1800 Old Bluegrass Avenue, Louisville, KY 40215
Please submit IT requests to Hazelwoo...@bluegrass.org
24 Hour Helpline 1.800.928.8000
CONFIDENTIALITY NOTICE: This message contains confidential information and is intended only for the individual(s) addressed in the message. If you are not the named addressee, you should not disseminate, distribute, or copy this e-mail. If you are not the intended recipient, you are notified that disclosing, distributing, or copying this e-mail is strictly prohibited.
From: ntsys...@googlegroups.com <ntsys...@googlegroups.com>
On Behalf Of Philip Elder
Sent: Wednesday, December 3, 2025 1:47 PM
To: ntsys...@googlegroups.com
Subject: RE: [ntsysadmin] LOL - and yet tears of sadness and rage
|
EXTERNAL EMAIL - This email was sent by a person from outside your organization. Exercise caution when clicking links, opening attachments or taking further action, before validating its authenticity. |
To view this discussion visit https://groups.google.com/d/msgid/ntsysadmin/a38de909a5b347488f9a55b047f923de%40MPECSInc.Ca.
Yeah, we don’t do cloud for sensitive stuff just because of the big compromises therein but also because the RMMs have been too.
So, we stick with on-premises. That mitigates a bit of the exposure.
Either way one errant click and done.
Philip Elder MCTS
Senior Technical Architect
Microsoft High Availability MVP
MPECS Inc.
E-mail: Phili...@mpecsinc.ca
Phone: +1 (780) 458-2028
Web: www.mpecsinc.com
Blog: blog.mpecsinc.com
Twitter: Twitter.com/MPECSInc
Teams: Phili...@MPECSInc.Cloud
Please note: Although we may sometimes respond to email, text and phone calls instantly at all hours of the day, our regular business hours are 8:00 AM - 5:00 PM, Monday thru Friday.