5 ms·
My argument for password expiry (300 days here) is my users have complained they can't keep using the password they use everywhere else.
by discreditable 7y ago
My argument for password expiry (300 days here) is my users have complained they can't keep using the password they use everywhere else.
- Wowfunhappy 7y agoAnd yet, you're also making it impractical for them to actually use a unique password, see what the GP said.
- discreditable 7y agoNothing stops them from using a unique passphrase. I am subjected to the same password requirements and use a unique passphrase every time. I see harvested passwords as a larger threat than bruteforcing, so some kind of expiry is important. Some users might use good, unique passwords, but most will not.
- criddell 7y agoAre you saying NIST and Schneier are wrong about this?
- discreditable 7y agoSchneier says "don't make people change their passwords unless there's indication of compromise" I make the assumption that the longer a password exists, the more likely it's reused and compromised. I don't have insight into every password dump, but I know my users reuse passwords a lot. I think a long expiry is the best balance in my environment.
- acdha 7y agoThat’s not an indication of compromise: just you increasing the odds of people creating predictable passwords. If you’re concerned about dumps, setup one of the services which checks against HIBP for known-leaked passwords and then put all of your effort into MFA (especially FIDO) because that will stop the kind of attacks which are common in this century: immediate use of compromised credentials, high-skill phishing, etc.
- Sohcahtoa82 7y agoThe point though is that if password changes are required, even with a long expiration time, people are only going to make minor and probably predictable changes to their password. If if you did a 1-year password expiration, and last year's passwords were compromised, then if the attacker figures out that someone's password last year was "uwethskjv9j29#18", then there's a good chance that the attacker is going to try logging in with the password "uwethskjv9j29#19" this year and "uwethskjv9j29#20" next year, and will probably succeed. You gain nothing from password expiration, other than annoyed users and and even more annoyed IT team who has to deal with lockouts from people that changed their password to something secure.
- sjy 7y agoSurely you gain more than nothing, even if it's not enough to justify the costs imposed on your users? I often hear that attackers will simply increment the number at the end of your password, but users apply many different "simple" changes and it's likely that you'd need to try a fair few tries to guess correctly. That might be feasible if you have the new password hash or you're targeting an individual victim, but if you don't, then the password expiry policy offers some defence in depth.
- dragonwriter 7y ago> The point though is that if password changes are required, even with a long expiration time, people are only going to make minor and probably predictable changes to their password. More significantly, if changes are required or weird composition rules used, people are more likely to store their password in a convenient unprotected form (historically, often paper kept next to their main computer, which is a risk, but these days the convenient form may itself by subject to remote compromise, making an even bigger risk.)
- thiagomgd 7y agoif a password expires every year, people are just going to use P@ssword2018, P@ssword2019 and so on... You require new passwords every year, done Require symbols, done lower and uppercase, done numbers, done
- anon73044 7y agoWouldn't you rather be sure and run the passwords through JTR or HIBP? https://news.ycombinator.com/item?id=21204297 https://news.ycombinator.com/item?id=21204297
- deleted 7y ago[deleted]
- kevin_thibedeau 7y agoI frequently have perfectly adequate strong passwords rejected because it doesn't have the anointed mix of special characters, or more infuriating, has ASCII printable characters that aren't accepted, like caps, digits, or symbols. The latter systems are 100% guaranteed to be storing unhashed passwords.
- wolco 7y agoThey can they just have to wait. At my previous role I added a number and kept increasing until it accepted the orginal password and I started the cycle again.
- 52-6F-62 7y agoI've done something similar with a role but alphabetical. A-Z, then AA-ZZ, AB-ZA and so on.
- Sylamore 7y agoBecause of minimum age rules, I just spell out the number if I can't recycle the old password yet. One of the reasons I don't do IT security any more is the attachment to old dogma like these kinds of password rules by auditors - they are the real barrier to making policies more effective.
- klyrs 7y agoI never wrote my password on a post-it on my screen. The post-it had tallies of the number of times I'd incremented the number at the start, and the number at the end. And I worked on my IT department, and then went over their heads, until they got smart about password expiration.
- justincredible 7y ago90 days here, 300 would be nice.
- _-david-_ 7y agoThey can change all their passwords every time one requires a change password.
- freehunter 7y agoHonestly that’s what I do at work. I have five passwords that all expire every 90 days and I made sure to get them expiring on the same date and in sync with the same password that matches the various policies and I just make minor iterations on that same theme every 90 days for all 5 passwords.
- benhurmarcel 7y agoMy workplace does this (every month). Everyone just appends a number. Either the current month, or one they write on a post-it on their desk.