DFAS password security

mickeyd

Give me a museum and I'll fill it. (Picasso) Give me a forum ...
Joined
Apr 8, 2004
Messages
6,674
Location
South Texas~29N/98W Just West of Woman Hollering C
If you receive military retired pay it will take many key strokes to access your pay data in the furure.

All thanks to PFC Brad Manning?

DFAS is implementing a new password security system for its MyPay online pay program. If you use MyPay, go to these pages to learn more about the password changes. The new system requires a lengthy 15 to 30 character password with the use of special characters. Plus, we have to change passwords every 60 days.
https://mypay.dfas.mil/mypay.aspx

Stronger Password Requirement
 
This is too much. From the announcement

  • Must be 15 to 30 characters in length
  • Contain at least two UPPERCASE letters
  • Contain at least two lowercase letters
  • Contain at least two numbers (0-9)
  • Contain at least two of the following special characters:
    • # (pound or number sign)]
    • @ (at sign)
    • $ (dollar sign)
    • = (equal sign)
    • ^ (caret)
    • ! (exclamation)
    • * (asterisk)
    • _ (underline/underscore)
  • Must NOT include any spaces
and then
If you must write down your password on a piece of paper, make sure it stays locked up in a secure place. If you save it to your computer, flash drive or other media device, make sure the document is encrypted and/or password protected.
So, keep it protected by another password that is less secure?

As for the "if you must write it down" (my emphasis) I couldn't even remember the rules, let alone a password that espires in 60 days. This is nuts. In most cases, more security is really less secure.

Thank God for LastPass.
+1
 
Yeah, I'm really looking forward to this. I currently have to use this system to access my federal civil service pay account, and when I retire I will still have to use it. Also...in 4 yrs I will be using it twice as much to access my military retirement account. Lovely.
 
Since I use 1Password for everything, I didn't find this requirement to be any problem. You need a 12 character password to get access to my 1Password, and you need a 25 character password to get access to my hard drive, so I feel fairly confident about security.
 
Back
Top Bottom