5 ms·
I've always thought the reason behind changing your password frequently was to thwart brute force attacks? Is that not the case?
by bwag 16y ago
I've always thought the reason behind changing your password frequently was to thwart brute force attacks? Is that not the case?
- peterwwillis 16y agohttp://en.wikipedia.org/wiki/Password_policy#Password_duration http://en.wikipedia.org/wiki/Password_policy#Password_durati... Just make your password very complex and the brute force is not much of an issue. Of course, not many people will go for that idea... Probably the best compromise is to review the advancement of password cracking technology over cost and compare that to the required complexity of a password to survive for at least 120 days without being cracked, and make your password complexity at least stronger than that. You can attempt relying on things like bcrypt (if your whole infrastructure happens to support such algorithms) but I think password complexity is enough to thwart most/all attacks.
- jules 16y agoCan you explain why changing your password would thwart brute force attacks?
- deleted 16y ago[deleted]