4 ms·
Forced periodic password change has got to be near the top of the list in terms of the dumbest things the IT world has blindly gone along with in the past decad
by beedogs 10y ago
Forced periodic password change has got to be near the top of the list in terms of the dumbest things the IT world has blindly gone along with in the past decade. Glad NIST finally agrees with me on this.
- dimino 10y agoI think that's unfair! It makes sense on first glance, right? People can't steal your password if it changes all the time. I personally find it unintuitive to think that people would give up on the "memorization" part if it became "too hard". It's true, and we know this from study, but to say it's "dumb" is unfair.
- Twisell 10y agoThe only password I need to write on a paper near my computer is of a client that require periodic change over his Vpnssl every 1 month. When connecting to it I must type it 3 different time in a context where password manager don't work. After a year of trying to keep track of the changes via a secured method (and at least 12 call to their IT so they reset the password without any identity check on their part) I finally resigned and write it down on paper and write the new one every time they ask me to change. Bonus fun fact : Theses idiots also truncated password at 8 characters but truncated in different manners on the 3 login steps required so it's only after 4-5 failed attempts at a secured corectbatterystapplehorse that I understood that weak password was mandatory by their rules... PS: And of cour rotation between Passwd1 passwd2 passwd3 passwd4 (then back to 1) was perfectly accepted and considered as safe
- Qwertystop 10y agoI ended up memorizing my home's old WEP key simply because, since I was the "tech guy" in the family, everyone would ask me whenever they needed to add a device (never mind that I was mostly just going to the password booklet and reading it out). Eventually I just stopped needing to look it up. I've since used it in some places, blended with a mnemonic for the specific site. 10 hex characters plus a string might not be the highest-security thing, but at least it's not going to fall to anything less than brute-force.
- kbart 10y ago"Forced periodic password change has got to be near the top of the list in terms of the dumbest things" Totally agree. I often encounter problems that go like this: UltraSecureSystem: Create a secure password. Me: "#@(J #!_04';/1~" UltraSecureSystem: Password must be at least 8 characters long, can't include special characters and consists of at least one upper case letter, one lower case letter and one number. Me: "Password0" UltraSecureSystem: Congratulations, your ultra secure password created! <After 1 month> UltraSecureSystem: Your password has expired, create a new ultra secure password. Me: "Password1" UltraSecureSystem: Congratulations, your totally new and totally secure password created!
- tajen 10y agoTip: Some systems only remember your last 3 or 10 passwords, so it's worth rotating up to Password9 and then coming back to Password0. Tip given by my boss who received it by his chain of command of old people who couldn't remember the password change. True story.
- Jaruzel 10y agoWhich is why in a lot of corporate systems, the password history is set to 13 last passwords. a) it prevents a 0-9 rotation, and b) it also prevents people rolling passwords based on month name or number.
- dzdt 10y agoWhy is why password rolling is then based on an alphabetical roll, or pure numerical increment, or month and year. No real entropy gain!
- daneyh 10y agoAugust2016 September2016 October2016 etc. pls don't hack me
- Jaruzel 10y agoI didn't say it was a good system ;) As the implementer, I've argued many times about it, but the ITSec bods always think they know best.
- deleted 10y ago[deleted]