4 ms·
I'm not entirely sure that I'd agree with this mentality. Sure, at a glance it sounds good. If the password has been safeguarded, there's really not much reason
by Raistael 7y ago
I'm not entirely sure that I'd agree with this mentality. Sure, at a glance it sounds good. If the password has been safeguarded, there's really not much reason to force expiration. However, wouldn't the age of the password reduce the security of it by default? The longer a password exists for, the more likely it is that it can be cracked, discovered by a misplaced Post-It note, or compromised by some other unknown security issue. With all the other security and privacy concerns in this thought process seems contrary.
- jugg1es 7y agoYou're ruining this for everyone.
- FlorianRappl 7y agoReality is that a password expiration policy quite often leads to password simplification (e.g., having an incremented number in the password, post its on the screen, ...). I'd prefer 2FA and (allowing / encouraging) longer / stronger passwords over change policies.
- Raistael 7y agoI prefer these methods as well, but password simplification is a user choice, not a causal effect. Any secure password generator and vault, keyfobs and various other methods are great ways to compensate for a password that expires every so often. While I'm not entirely in line with the idea of "forced" password expiration, it's often the only way to ensure that the end user actually updates their password regularly. There are definitely better ways than raw expiration. Why not present the user with a screen that basically says "hey, your password hasn't been changed in __ time, you'll need to fix that now to access the system" when they log in after the set time period?
- afiori 7y ago> it's often the only way to ensure that the end user actually updates their password regularly It is fair to point out that the relevance of this is dependent on your attack model. If you suspect someone is trying to crack your password then just a longer password is fine. If you suspect a leak then you actually need to change/update password.
- Raistael 7y agoThis is largely true, but we also exist in a day and age where computing clusters can fire off billions of guesses per second. Anything less than 16 digits takes a questionably small amount of time in comparison, when paired with some of the more advanced attack vectors.
- hackinthebochs 7y ago2FA is the solution. That way the password is only to protect against someone who physically has access to your keyfob (nosey coworker, thief, etc). Thinking of passwords as the solution to protect against sophisticated actors is the mistake.
- Raistael 7y agoProperly implemented 2FA, for sure. Having been on both sides of various types of 2FA failures, but I definitely agree.
- afiori 7y agoThis is the wrong argument here. With regards to brute force attacks changing password is only relevant if the attack time is comparable to the password turnover. If it takes one week to crack a simple password but you only change it every six month then you have ~1/24 chance to actually increase the attack time.
- loup-vaillant 7y ago> password simplification is a user choice, not a causal effect The two are not mutually exclusive. If you require users to change passwords regularly, and also make sure the new password is sufficiently different from the last one (like, most characters must be different or something), guess what the users are likely to choose of their own so called free will. And I'm not even speaking of how you must store a password to be able to tell that a new password is sufficiently different from all the old ones. (Hint: probably plaintext.) > […] "forced" password expiration [is] often the only way to ensure that the end user actually updates their password regularly. That does not work. I have defeated it in my last gig with this simple method: Complicatedpassword1 Complicatedpassword2 Complicatedpassword3 Complicatedpassword4 Complicatedpassword5 And I will do it again, because a complex password that never changes is much more secure than random crap that I will have to simplify just so I can remember it. Also good luck trying to defeat my strategy (or similar strategies) without storing more than a hash of the password, properly generated with a memory hard function like Argon2.
- mypalmike 7y ago> Also good luck trying to defeat my strategy (or similar strategies) without storing more than a hash of the password Enter Old Password: Complicatedpassword1 Enter New Password: Complicatedpassword2 Sorry, your new password is too similar to your old password. (Passwords are still stored and verified using hashing, but with a form like this, your most recent and new passwords are available in plaintext for comparison when you make the change.)
- loup-vaillant 7y agoCrap, I forgot about that. I guess I'll have to swap words if that ever happens: Complicatedpassword1 PasswordComplicated1 Complicatedpassword2 PasswordComplicated2 Complicatedpassword3 PasswordComplicated3 And if that fails, they win. Clearly they don't care about security, so I'll use a weaker password. And I will note it on a post-it and keep it in my wallet.
- Consultant32452 7y agoAt one of my previous employers the default password set by the help desk was [company_name]@123. They did a password audit and a full third of the employees had a variation of this password for their real password. It's not Google, but if it were, passwords were things like: google@321, google@456, etc.
- MithrilTuxedo 7y agoI think password expiration came about before two-factor authentication was as easy to use as it is now. Security concern around password age would be mostly obviated by 2FA.
- Raistael 7y agoMostly, if implemented properly, sure. I would agree with this.
- pishpash 7y agoYou can't force entropy out of people when there is only so much, regardless of how often you believe you're make them "change" passwords.
- dcow 7y agoI flat out do not buy the argument that by virtue of existing a secret becomes less secure. It's just not practically true. The assumptions needed for this to make sense are that people are actively attacking a given secret, that the new secret will be generated from arbitrary entropy (not depend in any way on the previous secret) and be a secret an attacker has already tried (otherwise the rotation was pointless). Furthermore, all keys already exist. When you "generate" one you simply pick from a large domain. The probability that two people (attacker and defender) pick the same key from the same domain does not change because someone already picked a key from the domain. It's certainly true that as technology improves and the mechanisms we build to secure things evolve new keys need to be used in order to stay up-to-date. But this amounts to secret rotation that aligns with evolving systems not arbitrary 90-day expiration policies. Much different argument. Keys should not be rotated.. security strategies should.
- rtempaccount1 7y agoI'd suggest that users who care , when no longer forced to periodically rotate passwords, will likely choose better passwords (I know I have, where I'm no longer required to do so). Users who don't care will still choose bad passwords, this is why 2FA is important :) Forced periodic password rotation was mainly security theatre. Most users just choose sequence passwords, so an attacker who gets one can easily work out the others. If you then take counter-measures to stop obvious sequences, you're heading into seriously user-unfriendly password policies, which is the kind of thing that gives security a bad name. Far better to make use of 2FA at that point.
- lone_haxx0r 7y agoEven if that natural decline in security was significant, it wouldn't be as significant as the insecurity introduced by forcing the user to change it.