8 ms·
The other part of this story I did not see mentioned is that I suspect that password expiration also makes organizations more vulnerable to social engineering h
by blr246 7y ago
The other part of this story I did not see mentioned is that I suspect that password expiration also makes organizations more vulnerable to social engineering hacks because legitimate users (I have done this) become locked out due to poorly managed password expiration, then have to call in to restore access. The use of insecure identity and authentication mechanisms like student IDs and security questions is a recipe for abuse.
Good riddance to password expiration.
- omh 7y agoUnfortunately we still have to have similar authentication methods for other password resets. Users have an alarming tendency to forget their passwords after a week or two of holiday.
- godelski 7y agoHonestly this just seems like there needs to be a better way. Maybe some multi-factor system that requires like a physical key and either a secret and/or some identifying thing.
- paulryanrogers 7y agoSome never memorize their passwords at all. Instead relying on 'forgot' emails and "Remember Me" features entirely.
- tty2300 7y agoWhich isn't even that bad of an idea. Some website basically use this as the only way to log in.
- erichurkman 7y agoSlack does this exceptionally well. If you forget which accounts you have, you can put in an email address and it will email you a list of your Slack accounts. If you forget your password, you can get a magic link that automatically signs in through a deep link into the app, no password needed.
- delusional 7y agoIt's such a cool idea. If you can reset your password using only your email, there's no security reason you can't just log in with it. It might even be better, since you can then add more annoying steps to the password reset strategy.
- lowkeyokay 7y agoBut Slack then must rely on the security of your email. If the site is dealing with sensitive information like credit cards, this could be a no go.
- rocqua 7y agoAny site that has a "enter your email for a reset link" feature relies on your email security.
- tty2300 7y agoAlmost every website in existence except the most security sensitive like bank websites will allow you to reset your password with email.
- nkrisc 7y agoWhat email based log in that doesn't use 2FA doesn't ultimately rely on the security of your email?
- vinay_ys 7y agoIn India, most mobile apps have phone number for username and OTP instead of password. Makes perfect sense for mobile apps. Except when OTP doesn't arrive due to congested sms networks. Or that your account gets hacked with sim takeover or sms MitM (both are currently unheard of in India).
- aerique 7y agoI think you just jinxed it.
- sriku 7y agoIt is one way to go "passwordless" .. though you're piggy backing on the security that your email system already has. Shameless plug of old post that describes how to restrict login to only the initiator even if login is initiated via an email link - http://sriku.org/blog/2017/04/29/forget-password/ http://sriku.org/blog/2017/04/29/forget-password/
- daveFNbuck 7y agoYou're relying on your email security either way, since anyone can trigger the password reset email if they get access to your email account.
- DalekBaldwin 7y agoThis breaks my workflow -- I almost never open the forgot-password email on the same machine I used to initiate the request. Usually I need to briefly access a personal account from somebody else's computer or my work computer, and when I'm told I need to check my personal email, I only want to open that on my phone.
- nitwit005 7y agoI have wondered if some web pages effectively have this as the main log in method. If you have a hurricane tracking page, everyone is going to forget their passwords in between hurricane seasons.
- brigandish 7y agoI wondered about this too and asked about it on the security stackexchange forum in case I was overlooking some glaringly obvious reason not to. Turns out that most thought it was reasonable too, though maybe too frustrating for some. https://security.stackexchange.com/q/12828/8518 https://security.stackexchange.com/q/12828/8518
- reaperducer 7y agoI've seen Blendle and a couple of other web sites do this. You go to the login page, and your choices are federated login, standard login, or a one-time login e-mail.
- aikinai 7y agoYahoo Japan (not really related to the defunct original Yahoo and still very successful in Japan) recently abolished passwords for new accounts. You can only login with reset emails or SMS codes, which is pretty annoying.
- wilsonrocks 7y agoBulb energy supplier in the UK trialled this - they soon switched due to complaints although I didn't really mind it. Assume it was due to the inconvenience of not being able to remember password/stay signed in.
- gpm 7y agoSteam has nearly done this for me. Oh, it has a password. But if I remember my password I have to check my email and copy and paste a code from there. And if I forget my password I have to... check my email and copy and paste a code from there... really not much point to the password.
- melicerte 7y ago
- kerouanton 7y agoIndeed. On sites I have to register but know I won't go frequently I enter a random password I don't even write down, relying on the Forgot password feature if I ever need to come back later.
- Aeolun 7y agoAlso not helped by the fact that passwords have to include every symbol and their mother, cannot include sequential digits, cannot include sequential letters, cannot include any letter of your name, and a bunch of other inane rules that could be changed to simply having a minimum length of 12 instead of 8...
- reaperducer 7y agoA couple of years ago one of my banks "upgraded" its web site, forcing me to change my password to comply with its revised password guidelines since my old password was no longer permitted. The result was a password that was shorter, less varied, and less secure than the previous one. Good job, Chase.
- setzer22 7y ago> my old password was no longer permitted. But how did they know? They should just have the hash...
- eicnix 7y agoIf they implemented it properly they could have checked the current password against the revised guidelines on the next login. No need to store it in plain text
- uberswe 7y agoThe website can check the password during login without storing it in plaintext
- systemfreund 7y agoThe login form usually sends the password in cleartext and it's then hashed on the server-side prior to comparing it to the hash stored in the database. So they can just determine the password's strength at the time when the user is logging in
- rahoulb 7y agoI had a similar problem with Lloyds - every time I wanted to transfer money using the mobile app, I had to type in the password manually as they had disabled the "paste" option. Given my password was auto-generated and 16 characters long - and the password field wiped every time I did an app-switch, I just gave up.