7 ms·
NIST advises services to not require that passwords be changed periodically
- newman314 9y agoI think this is silly. Anecdotally, I've had good success forcing longer passwords while at the same time, introducing people to password managers. Doing only one or the other does not have the same uptake but we recently went through and forced everyone to reset their passwords. We're now up to 16 chars, I'd like to get to 30 (or to a point where it's a pain to type it in) but baby steps, I suppose.
- csydas 9y agoWe took a different approach at my last job when we revisited our entire identity management approach. We were a University with Federated logins across a few dozen system, and our password rules had honestly spiraled out of control because the system hadn't been constructed in such a way to restrict access easily. During the rework, we focused on a few things primarily: 1. Reduce password complexity, enforce legnth 2. Restructure account creation around least-privilege principal, so that access had to be granted, not just created during account creation, and also allow fast and easy addition and removal of access to system as part of the Management System 3. Revisit password expiries based on level of access and relative strength of password (as determined by zxcvbn) Students and low level staff loved it - if you had a standard account and didn't have any access to anything sensitive that didn't belong to you, your password could sit untouched for up to 2 years I think if it met the strength requirements. Those with access to actual sensitive data (student records, finances, etc), were held to a higher class of password complexity and would suffer a rotation penalty if they didn't have a sufficiently complex password; this mostly did away with the number of people with very common passwords, though it didn't go without a lot of fighting for some of the administrators, which, as I remember the discussions anyways, were more pride issues than anything. We used that as an opportunity to roll out password managers
- kevhito 9y agoCan you back up these recommendations with actual studies or research papers? Or are you just making up your security strategy by gut instinct here?
- ScottBurson 9y agoEven if it's the latter, they're actually thinking about what they're trying to protect and what system would work best to protect it. That has got to be an improvement on the mindless, cargo-cult approach to security that most organizations take.
- kevhito 9y agoReally. The article cites NIST and one scientific study (of which there are many). And your response is "Anecdotally..." ?
- dsacco 9y agoWhy do you think it's silly? There are only two reasons to change a password: 1. The cover time (expected duration of secrecy) is about to expire, either due to advances in technology or because it was too small to begin with; or 2. The password was compromised and is no longer secret. If a password has not been compromised and is sufficiently strong as to not be crackable without a server farm and hundreds of thousands of years, it doesn't make sense to change it.
- snakeanus 9y agoWhy not just move to public key authentication then?
- 5706906c06c 9y agoThe problem is that most have adopted password managers and two-factor, which means the guideline will be largely ignored.
- interfixus 9y agoMost? Do you really think so? In my experience, the vast majority of everybody is still bumbling ahead with post-it notes and simple, memorised passwords shared all across the board.
- 5706906c06c 9y agoI'm so sorry for you and your job, I guess.
- jjawssd 9y agoWhat is your definition of most? 1%?
- 5706906c06c 9y ago1%? What does that mean?
- raarts 9y agoIsn't that obvious? 1% of all users.
- sndean 9y agoThe first reasonable statistic that I could find was 1%, for the percentage of individuals in a large organization that used password managers [0]. Or maybe it's 8%, in a survey [1]. That 1% figure is pretty old, and people lie in surveys, so it's possibly >1% and <8%. The vast majority of people don't use password managers (or 2FA). [0] https://www.internetsociety.org/sites/default/files/08%20why-do-people-adopt-or-reject-smartphone-password-managers.pdf https://www.internetsociety.org/sites/default/files/08%20why... [1] https://www.passwordboss.com/news/survey-finds-vast-majority-of-americans-memorize-or-write-passwords-on-paper/ https://www.passwordboss.com/news/survey-finds-vast-majority...
- Spare_account 9y agoNIST doesn't "Advise Against Periodically Changing Passwords". There is no issue with periodically changing passwords in and of itself. NIST is acknowledging that the typical user when faced with a password policy that requires a regular password change will choose a weaker password. NIST is advising against imposing a requirement to periodically reset passwords. Maybe I'm nitpicking but the title as it currently stands is misleading in my opinion.
- dsacco 9y agoI disagree. In principle, every time a password is changed is a point of failure - it's additional overhead that has the opportunity to go wrong. If a password does not need to be changed, don't change it. Set it and forget it. If you generate strong passwords, store them securely in a password manager and use different passwords for each account, you shouldn't need to force a password change unless the password is compromised or technology evolves to make it insecure.
- chronic940 9y ago> store them securely in a password manager and use different passwords for each account You are about the 2% of the tech crowd (i.e, bay area software/data people). The vast majority of engineers do not use a password manager, let alone the entire US populace. You severely overestimate the amount the average person cares about password security.
- wayn3 9y agoid much rather have a reasonable solution for widespread 2 factor authentication than this password mess. with my bank i have a password, an app on my phone that generates a key and if i perform significant transactions, they call me to confirm before processing it. the idea that i'm going to use a different password for every stupid site out there that i have an account with is a bit silly. if someone desperately wants to compromise some of them then so be it. hijack my twitter if it makes you feel better. im not going to waste mental energy on securing social media. "just use a password manager" sounds cute. password managers are compromised, too. password managers are about as trustworthy as the people who operate them. theres no way im handing my passwords for bank accounts over to some random company and for passwords that protect pointless internet nonsense, im not going to use one either because its irrelevant. you can invoke this whole "password managers are secure" hoohaa. if they ACTUALLY encrypt your passwords properly and ACTUALLY dont save them on their own servers for whatever they want to do with them later, then yes, they probably are secure. but theres no way to be sure that thats the case. Trusting a password manager introduces more uncertainty into your password woes than they will ever make you more secure, if you really think this whole thing through. the other issue with a password manager is that in theory, they work across platforms. that ends rather abruptly when youre not in a browser and need to enter a password into an app on your phone.
- deleted 9y ago[deleted]
- lholden 9y ago"The National Institute of Standards and Technology (NIST) is no longer recommending people periodically change their passwords as part of the organization’s new draft of its Digital Identity Guidelines." Untrue, misleading, and possibly harmful. NIST isn't recommending USERS stop changing their passwords. That would be insane. They are recommending that services stop enforcing periodic password changes on users because it ends up hurting the user in the long run. (Ie, passwords should be easy for users and hard for attackers).
- ScottBurson 9y agoI think the keyword is "periodically". They're not saying not to change passwords for any reason; they're just saying not to do it solely because the password has been in use for some fixed amount of time. That recommendation applies to users as well as to services setting password policy.
- devonkim 9y agoYeah, I think the title could be better stated as "NIST Advises Against Mandatory Password Rotation Policies."
- LinuxBender 9y agoNIST have an interesting history around security. One such example would be AES. They favored Rijndael over Serpent, despite Serpent clearly winning on technical merit. Also, Rijndael is the one cipher that intel have offloaded on their chips and even called it AES-NI vs. offloading several ciphers. I agree with some comments here that size matters. It is trivial to put a series of characters in between 2 to {n} words you can easily remember. ____This____Is____Number____42!____ and I would remember it is 4 _'s around each word because there are 4 words/numbers. More sensitive content should equate to more words; and therefore, more of the buffer characters. You can even use this to defeat keyloggers. Open up a prompt that you can type in, then type a bunch of a character. Then use your mouse to select the number of characters that represents your buffer character length, or a portion of it. Then copy-paste as required. Keyloggers will capture cntr-v but they won't capture how many characters you selected. For those concerned about password managers and keyloggers, don't put your actual password in them. Leave off something, somewhere in your password. Maybe the start of your pw actually contains buffer characters that you know to type or paste. A majority of folks won't be bothered to do any of this. I am just sayin', it's super easy once you train yourself.
- gruez 9y agoWhy even bother with these weird rules? just use a password manager, generate a secure (> 128bit entrop) password, and be done with it. Also, keepass has something like your keylogger foiling method, called "2 channel obfuscation".
- LinuxBender 9y agoUse whatever option you are comfortable with. I know people that can't bother to use more than 1 password everywhere and certainly can't use more than 6 characters.
- alister 9y ago> For those concerned about password managers: Leave off something, somewhere in your password. I like the idea. So what you suggest is to manually type, say, "7&>>", before or after every password entered by the password manager? Or to copy-paste the "7&>>" from somewhere. A password manager is essential for good security (and I use one) but I'm concerned that it can be devastating point of failure. It can be worse for highly-organized people who keep absolutely everything in there. It's a single, up-to-date database in a nice standardized format with known filenames and clearly labeled data that lends itself to automated malware that can seek it out when your password manager is open/mounted/decrypted. As you said, a majority of folks won't be bothered, but a good extra step for someone highly security conscious.
- jamesaross 9y ago"In addition to ditching the requirement for regular password changes, the NIST is also advising sites to allow users to create passwords that are at least 64 characters long and include spaces so people can create pass phrases that may be easier to remember and to ditch special character requirements." Relevant XKCD: https://www.xkcd.com/936/ https://www.xkcd.com/936/
- antaviana 9y agoI would say that the main reason for periodically changing a password is to be better protected from data theft in those who store the password (read yahoo hack and family). That said, I hate changing passwords.
- milkthefat 9y agoThis is great, unfortunately considering this is only draft I imagine it will be a considerable amount of time to trickle down through the "compliance standards" we are required to enforce. I do look forward to the day I no longer have to change my password every 30 days though.
- tyingq 9y agoAgreed. As it stands today, PCI, Sarbanes Oxley, HIPPA, and other drivers are used as hammers to force password change policies. Even if they don't mention it directly, some audit firm tosses it in as a best practice to support something more generically stated in the standards.
- rocky1138 9y agoThis is a terrible article which autoplays a loud video and has a misleading title.
- devsigner 9y agoI change my password manager more than I change my passwords. Always healthy to investigate alternatives to KeePass and LastPass
- hackbinary 9y agoUhg, ibtimes is one of those annoying sites that autoplays video. There is chrome plugin that blocks autoplay for video and audio, but you then have to give it rights to access all data on webpages. How does this square with with online purchases where you put your credit card in?