In your work calendar: Settings -> Settings for My Calendars -> Access Permissions -> Get shareable link.
In your personal calendar: Other Calendars -> Subscribe to Calendar
With this, I've managed to remove all other traces of work from my personal phone.
How in the world do you do that? Subscribe to Calendar isn't even possible with Office 365, right? You have to use From URL, to which you give the .ics URL, which Google Calendar normally pulls a couple times a day. Is there a different mechanism you use?
Hahahahahahaha. Good one.
I work at a department that's all about data quality and integrity, and we have super bureaucratic processes to regulate access to data, but you don't want to know how much data lives in Excel files; an issue I'm constantly trying to address.
No internet access at on laptops or only with a sim card which only allows connections to the VPN bastion host etc. Direct Internet on premise is a no-go as well, obviously. So no checking stack overflow if you've got any issues
They still leave infrastructure with default passwords exposed to the internet and implement questionable password policies for their customers... But they do everything they can in order to sabotage their employees!
Maybe make it a point to put your passwords on a sticky note stuck on the monitor prominently on display if $work requires you to change passwords that frequently?
I've been confronted with exactly this a short while ago, and even produced Microsoft's official stance on this (against). But in the end, their argument really boiled down to "but my checklist says so".
Microsoft's [0] first entry of "Common approaches and their negative impacts". With a reference to the FTC website. [1]
[0] https://docs.microsoft.com/en-us/microsoft-365/admin/misc/pa...
[1] https://www.ftc.gov/news-events/blogs/techftc/2016/03/time-r...
https://pages.nist.gov/800-63-FAQ/#q-b05
Q-B05: Is password expiration no longer recommended?
A-B05: SP 800-63B Section 5.1.1.2 paragraph 9 states:
“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”
Users tend to choose weaker memorized secrets when they know that they will have to change them in the near future. When those changes do occur, they often select a secret that is similar to their old memorized secret by applying a set of common transformations such as increasing a number in the password. This practice provides a false sense of security if any of the previous secrets has been compromised since attackers can apply these same common transformations. But if there is evidence that the memorized secret has been compromised, such as by a breach of the verifier’s hashed password database or observed fraudulent activity, subscribers should be required to change their memorized secrets. However, this event-based change should occur rarely, so that they are less motivated to choose a weak secret with the knowledge that it will only be used for a limited period of time.
That said, there is a place for 30-day rotation. That's when the so-called "password" is actually a shared secret for extremely high-value systems. Payment gateways, for example.
Should we even attempt to let the user define such shared secrets? If 30-day rotation is good, surely 30 second rotation is better? Perhaps we can replace such "passwords" with some kind of one time PIN (OTP) or some generated pass phrase only valid for n minutes?
I am all for having transient secrets, but without an extremely well integrated and robust vault they would be unmanageable. Plus asymmetric handshakes are computationally really expensive, so you don't do them all the time.[ß] The 30-day rotation period for these types of secrets is merely a reasonable compromise between "assume all shared secrets will be compromised" and the human factor.
ß: a friend set up a dedicated payment gateway device for a UK challenger bank. For just one card issuer. That thing can supposedly run at 10Gb line rate, so doing asymmetric crypto frequently would murder performance and latency.
Though, to be honest, at this point I believe that humanity should just abandon passwords for all but the most unimportant of things (e.g. your account on some hobbyist forum), at this point they just have too many downsides and most people seem to be unable to handle them properly.