7 ms·
I never understood thecidea of having to change my password periodically. The password was good last month, why isn't it good now?
by TwoBit 10y ago
I never understood thecidea of having to change my password periodically. The password was good last month, why isn't it good now?
- Spooky23 10y agoIt isn't about password hacking. It's a control to limit the scope of people sharing or otherwise compromising passwords within the office. It happens, all of the time.
- shakna 10y agoWouldn't it encourage people to write down their passwords and leave them in plain sight? Increasing shared passwords within an office space?
- gregmac 10y agoExcept it doesn't help with that, at all. Many people use predictable rotations (incrementing number, date appended), so if you know one, you know them all. Also if they've shared it once, why would they not share it again? Put another way: why is making them regularly reset their password going to make them suddenly follow security protocol, when it didn't the last n times they had to change their password? If the office thinks it's okay to share their password it's also a symptom of several things: * Lax security environment, with not enough emphasis on security training and importance. * Poor senior management. There should be reprimands for violating security rules, as severe as losing your job for repeat offenders, and obviously IT can't do this on their own. * Bad work environment provided by IT. Why are they sharing passwords to begin with? Maybe the environment is overly locked-down with too many restrictions, or maybe the collaboration tools are just bad or missing. Fix those, the password sharing stops.
- vbezhenar 10y agoIt's trivially solved by comparing new password to all previous passwords and decline if they are similar. And if they wrote their passwords on the stickers, they should be explained that it's not appropriate. I agree that this approach is not very user-friendly.
- gregmac 10y agoI don't think it's trivial to find similar password for multiple reasons. Comparing old passwords without plaintext is really hard and at best inexact. Storing them plaintext (or even reversibly encrypted) is completely stupid, of course. Even if these technical problems could be solved, sequences like: November6, December7, January8 are not "similar" but easily predictable. Even this sequence is probably not hard to figure out if you look at a keyboard: Secret1 Drvtry2 Ftbytu3 Deeper though, what security threat is this actually mitigating? Bad passwords caused by rotation requirements that are needed because of bad company policies, training and practices? Is there a security equivalent of "yak shaving"?
- vmarsy 10y agoHow would you do the comparison? Wouldn't it require storing all the previous passwords in plaintext? If only the hash and salted password is stored, as recommended, how would you know that "myOldPassword21" and "myOldPassword22" are similar ?
- apk17 10y agoYou make the modifications and store those hashes as well. Can't have a new 'similar' algo for past pws, obviously.
- xamuel 10y agoIf you store N variations, a random guess has N chances to hit one. Once an attacker knows a variation, they may be able to use it to narrow down on the real password.
- ascorbic 10y agoSame way you check if the password is correct. Check against the old hashes. When the user sets the new password, if it looks like it matches an iterative pattern (i.e. if it ends in a number) then test the previous few from that sequence against the old hashes. Note, this is still a terrible idea.
- Spooky23 10y agoI didn't say it solved all problems. I said it was there to address that issue. It does help to limit the scope of who has passwords. Certainly not a perfect solution, but it isn't completely ineffective either.
- vidarh 10y ago> It does help to limit the scope of who has passwords. Only if the rotation isn't predictable. If I receive "password3" and it doesn't work and Joe who shared it with me isn't available, I probably wouldn't think twice about trying "password4".
- wbillingsley 10y agoI would have thought it was actively detrimental to ask people to come up with a new one every month. I can just imagine villainous hacker sitting there thinking "Blast, none of the employee's passwords were in my database of common passwords. Never mind, next month they'll have to have a whole new set and maybe one of those will be."
- tptacek 10y agoIt's fundamentally the same principle as forward secrecy: that the compromise of one password doesn't permanently destroy the security of the systems to which that password applies.
- billhathaway 10y agoThe justification I heard was in case your password was leaked/hacked (and nobody knew), it wouldn't be good forever. I'm not supporting that position, just what I heard many years ago when talking with a security person.
- landr0id 10y agoI work in security and yes, it definitely helps in some cases with preventing lateral movement. Since servers aren't rebooted often, if I choose to run mimikatz to dump creds off of the server and steal a user's password, that password may as well be useless if the user logged in long enough for a password reset to have been enforced in that time.
- alcari 10y agoThe rationale was that if, password hashes got compromised, the attacker would only have until the next forced rotation to crack the passwords and take over accounts. edit: or, in particularly terrible systems, if plaintext passwords were leaked. Of course, that's only useful if it doesn't affect any other password security concerns, and it turns out that users who are forced to change their passwords frequently pick worse passwords, which is a bigger problem than the scenario this was supposed to protect against.
- dmfdmf 10y agoOr put them on a yellow sticky under their mouse pad.
- guelo 10y agoA sticky note is very secure against remote attackers.
- benchaney 10y agoWhich is good enough in most cases. If an attack can walk in and physically tamper with you computer peripherals you generally have bigger problems.
- hackuser 10y agoAs a very general rule, most attackers are insiders.
- user5994461 10y agoInsiders are easier to identify and deal with. Be it a rogue employee or a nasty sister.
- mulmen 10y agoThere is no password policy that protects against rubber hose cryptanalysis.
- rtpg 10y agoIf, for whatever reason, your password ends up somewhere (even some sort of keyboard buffer?), but is found a couple months later, then it can't be used anymore. It's also a similar rationale to password resets. The e-mail might end up in some leak somewhere (see WikiLeaks), but the link won't be valid anymore. It doesn't stop all classes of security issues, but it does make the data time-sensitive. Think about all the account leaks that happen. The data is rarely current (usually a year+ old).
- AstralStorm 10y agoIf you can get such sensitive data, you can install a live root kit instead and get fresh passwords. So the policy is ineffective.
- rtpg 10y agoThat's not always true. For example, imagine if someone compromises one of your backups. Some hard drives were stolen from the office or something. In there you had your password written in a text file ( because you're that kind of person). The attacker still doesn't have access to your computer. But they do have access to your password from the time of backup. A disgruntled employee remembers the password of a former coworker. At one point the password will change, so the window of opportunity is smaller. It's not perfect, obviously, but in a lot of office environments passwords are easy to gleam. Another argument for password rotation: it usually forces people to keep different passwords per service. Without rotation, people tend to use the same password for everything There's a trade-off, but it doesn't accomplish nothing
- Falkon1313 10y agoIt's a halfhearted attempt to protect against vulnerable zombie accounts. When someone leaves for whatever reason, their account (if not terminated) still has access. Someone could hack in (or the former user could try to log in at a later date) and get that access. The policy of "If you don't change your password in the next 7 days, you will have to contact IT to reset it.", (along with actually locking out the account if the password isn't changed in time), could greatly reduce potential abuse of those zombie accounts. A large organization, especially one with lots of turnover, could accumulate thousands of those zombie accounts over the years. Of course, the proper thing to do would be to deactivate the account when someone leaves the organization. But if the organization doesn't have it together enough to deactivate and reactivate accounts properly, they might rely on the time limit as a fallback. The reason your password isn't good now is that someone doesn't have the info they need to do their job (deactivating accounts) properly, is lazy, or is paranoid. In any case, it's a signal that the organization that's requiring you to change your password can't manage account deactivation.
- AstralStorm 10y agoHeck, disabling unused accounts automatically is good enough.
- discreditable 10y agoIn my organization I've noticed one benefit of forced changes is it causes their "work" password to be different from their $EVERYWHERE_ELSE password. I preach to them they should not have an $EVERYWHERE_ELSE password, and should definitely not use it at work. But they do anyways.