5 ms·
The rationale was that if, password hashes got compromised, the attacker would only have until the next forced rotation to crack the passwords and take over acc
by alcari 10y ago
The rationale was that if, password hashes got compromised, the attacker would only have until the next forced rotation to crack the passwords and take over accounts.
edit: or, in particularly terrible systems, if plaintext passwords were leaked.
Of course, that's only useful if it doesn't affect any other password security concerns, and it turns out that users who are forced to change their passwords frequently pick worse passwords, which is a bigger problem than the scenario this was supposed to protect against.
- dmfdmf 10y agoOr put them on a yellow sticky under their mouse pad.
- guelo 10y agoA sticky note is very secure against remote attackers.
- benchaney 10y agoWhich is good enough in most cases. If an attack can walk in and physically tamper with you computer peripherals you generally have bigger problems.
- hackuser 10y agoAs a very general rule, most attackers are insiders.
- user5994461 10y agoInsiders are easier to identify and deal with. Be it a rogue employee or a nasty sister.
- mulmen 10y agoThere is no password policy that protects against rubber hose cryptanalysis.
- e12e 10y agoSure there is. I believe the classical approach is cyanide in a false tooth.
- AstralStorm 10y agoA less classical is divulging a self destruct/lockout password. Pity so few systems support this.
- jon-wood 10y agoThat's going to go badly for you the moment the attackers realise what you've done. Admittedly they'll no longer be able to compromise the account, but you better really care about that.
- inopinatus 10y agoHow about ... a duress code that diverts to a system that looks like the real one but actually contains disinformation (possibly including a misdirection that makes them think you were on their side all along, so that they let you go)
- vidarh 10y agoI'd say that in most cases, the safest approach to a duress code would simply be to give real access to the system, possibly with lower privileges if it can be done without too much suspicion, while also triggering an alarm. The cost of maintaining a sufficiently real-looking system is likely to be very high, with the very real risk that it won't fool an attacker.
- nkristoffersen 10y ago
- function_seven 10y ago> it turns out that users who are forced to change their passwords frequently pick worse passwords I can vouch for this. My rotating password at work is _______1, followed by _______2, then _______3, and so on. If a year-old hash gets cracked, it won’t take a rocket scientist to know that the password right now is _______4.
- deepfriedrice 10y agoEveryone I know does some variation of this. I'm currently enumerating gen 1 pokemon.
- d6e 10y agoSo one day you'll have "Mew" as a password?
- Already__Taken 10y agoNo silly, "MewMewMew" when it's too short.
- Infinitesimus 10y ago"M3wM3wM3w*" to satisfy special character requirements
- zie 10y agoGet a password manager already, and let it just generate random passwords for you. Typing in passwords is so lame. :) If you are on macOS I highly recommend https://github.com/ravenac95/sudolikeaboss https://github.com/ravenac95/sudolikeaboss (and by extension 1Password).
- Tactic 10y agoThis would be fantastic if work allowed me to install one. Sadly, some of us work in locked down environments so resort to such silliness to get through the work day.
- user5994461 10y ago> The rationale was that if, password hashes got compromised, the attacker would only have until the next forced rotation to crack the passwords and take over accounts. In all fairness, it's a fair assumption. There is an attack vector where one gets an old password from 8 years ago by whatever means... and it is still valid. The execution was terrible though. People started forcing password change every month [which is overkill to stop an attack that has a multi year timespan] and it created a whole new set of disasters.