5 ms·
Lots of people may have recently switched to a password manager, and now use it to store old passwords that they haven't regenerated. It's very likely a common
by whichdan 9y ago
Lots of people may have recently switched to a password manager, and now use it to store old passwords that they haven't regenerated. It's very likely a common use case.
- wlesieutre 9y agoThis was me a couple months ago. Had one password that I reused on a bunch of websites where I didn't particularly care about security. Eventually decided to give them all stronger unique passwords (because why not) and it was a pretty easy process because the password manager could show me all the sites with duplicate passwords.
- r3bl 9y agoHeck, you don't even to switch to it recently! I've imported my passwords from Firefox's password manager to a dedicated one a few years back, and I've been generating new passwords ever since. There's still dozens of occurrences of the one-password-for-all-services I've used previously, because nobody will go through the hassle of changing passwords in hundreds of online services. I do change it whenever the autofill appears too short to be randomly generated, but I still didn't get rid of all of them. With that said, I'm not using 1Password and I've already checked my old password in Troy's service to make sure it wasn't in a breach.
- kuschku 9y agoPassword rotation is a major issue. If we'd use something like certificate auth it'd be less of an issue, but currently password managers are a horrible trend because they encourage using your password for a service for kany years. Ideally you'd rotate them every 60 days. Automating that is hell. It'd be much nicer if we could just use OIDC with user-configurable endpoint.
- mnutt 9y agoHow do password managers make password rotation any worse? If anything, they at least keep a record of which sites need password rotation.
- kuschku 9y agoWe used to have OpenID in the past, now that password managers exist, efforts to fix the problem at the root have been stalled. In fact, Android implements now on OS level an API for password managers, but no way to easily authenticate through a third party app. Password managers are "good enough" that few people care about better solutions anymore. Personally, I'd prefer to see client side certificates, or OIDC login everywhere, with short lived session tokens, and proper U2F 2FA.
- jedberg 9y agoPassword rotation has been shown time and again to be worse than just using a unique strong password. With rotation, there is a tendency to just use the same password but increment a digit at the end, or to write them down because people forget them. A password manager helps with this, but if you're using a password manager, then you can use a different password everywhere. Password rotation was recommended in the days when people used the same password everywhere and had to memorize them because password managers weren't a thing. Password rotation gains you nothing if you're already using strong, unique passwords. The best it will gain you is preventing your account from being accessed if they have already breached the password file, cracked it, and come back after the rotation period. But at that point they've already had access to the system and your password is meaningless anyway, so you didn't actually gain anything.
- kuschku 9y agoI'm talking about automated password rotation. A new 128 byte random base64 password every month. Rotating credentials is important, even if you automate them. For the same reason that Let's Encrypt only provides certificates with 90 days validity, and that OAuth2 Offline tokens are usually limited to 90 or 180 days. Ideally we'd use OAuth2 for everything, as that'd allow proper usage off offline tokens that allow the client to generate short lived session tokens, but we don't, instead we're using passwords everywhere, and we'd ideally want to have the same validity there. The optimum would even be using challenge response authentications, or client side certificates. This isn't a comparison of manual password management to password managers, but a criticism of password managers when compared to 30-day rotation cycle of client-side certificates.
- eridius 9y agoRotating passwords is only important if the site has been compromised (or you've been compromised, such as being phished). For the former, 1Password already has the Watchtower functionality where it tells you if a site is known to have been compromised since your password was generated, and for the latter, well, if you're being phished then you'll probably figure it out pretty quickly when the attacker steals your account. In any case, if you really want to rotate passwords, 1Password has a "Security Audit" section with sections for "3+ years old", "1-3 years old", and "6-12 months old" passwords (and duplicate passwords, and weak passwords, and watchtower alerts), so you can rotate if you want to.
- dsacco 9y ago> Ideally you'd rotate them every 60 days. This isn’t correct. Password rotation is a function of desired cover time (how long you want to maintain confidentiality) and password strength (approximate entropy and complexity). If you randomly generate a password with 20+ mixed case alphanumeric characters, it’s theoretically safe against offline brute forcing attempts for more time than the universe has existed. Statistically speaking, you gain virtually nothing by rotating such passwords unless you know they’ve been compromised. On the other hand, you impose a significant security liability through usability friction.
- dawnerd 9y agoAnd theres some sites where random passwords just don't work because of dumb password rules so hand making them is easier. Also still nice to know when a password, randomly generated or not, is released out there in the wild.