4 ms·
"Periodic password expiration is a defense only against the probability that a password (or hash) will be stolen during its validity interval and will be used b
by EnderWT 7y ago
"Periodic password expiration is a defense only against the probability that a password (or hash) will be stolen during its validity interval and will be used by an unauthorized entity. If a password is never stolen, there’s no need to expire it. And if you have evidence that a password has been stolen, you would presumably act immediately rather than wait for expiration to fix the problem."
Full post:
https://blogs.technet.microsoft.com/secguide/2019/05/23/security-baseline-final-for-windows-10-v1903-and-windows-server-v1903/ https://blogs.technet.microsoft.com/secguide/2019/05/23/secu...
- thaumasiotes 7y ago> If a password is never stolen, there’s no need to expire it. And if you have evidence that a password has been stolen We've been seeing the point "your personal information is already out there, in the hands of hackers" recently. This cleft seems oddly blind to the possibility that a password has been stolen, but you have no evidence of the fact.
- Retric 7y agoIf that’s the fear then all passwords should expire at the same time. Otherwise if you reset every X days, hackers will always have access to some accounts X days.
- setr 7y agoIn the current method, possible access risk is staggered, such that you only have access to some accounts, for some days. In your method, you have access to all or none, for some days. Staggered seems preferable. Note that I’m only arguing your reasoning, not the broader point of password expiration
- Retric 7y agoOn day zero staggered means they still have access to ~100% of accounts. Hackers with access to 100 million accounts generally can use any of them, but not all of them. So, in practice access to 1% or 100% of all accounts may be equally damaging.
- marzell 7y agoDoesn't that only matter if you use the same password for more than one account?
- AmericanChopper 7y agoThis doesn't do a very good job of explaining the actual threat modelling that goes into this policy. Password rotation helps to minimize the impact of passwords that are compromised in two scenarios: 1. If the passwords are stored improperly by the service provider. 2. If the passwords are stored properly, but are weak and easy to compromise from a hash. The idea is that both of those problems can be better solved in other ways. Number 1 is better solved by doing some due diligence with your service providers. Number 2 is better solved by using strong passwords, where it wouldn't matter if the hashes are compromised. Number 2 comes down to encouraging better password behaviour among your users. Not enforcing password rotation is seen as a way of encouraging better password behaviour by removing onerous requirements that do not actually contribute to the desired outcomes (using stronger passwords). In addition to that, it's believed that the theoretical trade off between the two approaches is minimised by focusing more attention onto proactive monitoring. The reasoning is based on looking at opportunity cost, and the idea that users are more likely to comply with easier to follow policies. There are better areas of security for administrators to be focusing their attention on, and you're more likely to have a positive impact on peoples behaviour the less you inconvenience them (or ideally, your policies would actually increase convenience for them).
- matt_morgan 7y agoThis ignores the fact that most people use the same password everywhere, given the opportunity, and you have no idea what website has been breached. I.e. if you don't expire passwords, most people will use the same password everywhere, and you don't know when a compromise has happened, because it happened on some totally other network.
- dwaite 7y agoThis doesn't need to be solved via time-based expiry though - you can use a breach list (like checking https://haveibeenpwned.com https://haveibeenpwned.com on registration,login, and password change). Even an aggressive password change policy is typically one month since last change, which would give a long window for access. Secondary factors, if at no other time then on first use of a machine, are also a good technique to prevent password breaches from spreading into your system.
- deleted 7y ago[deleted]
- seqizz 7y agoList-checking can't help every time. Some people use "clever" tactics to use slightly different passwords (hunter2fb for Facebook, hunter2tw for Twitter).
- kebman 7y agoAssuming there is no zero day exploit. But then I'm paranoid.