9 ms·
Bruce Schneier's summarization [0] of NIST's revised recommendations: 1. Stop it with the annoying password complexity rules. They make passwords harder to rem
by orand 7y ago
Bruce Schneier's summarization [0] of NIST's revised recommendations:
1. Stop it with the annoying password complexity rules. They make passwords harder to remember. They increase errors because artificially complex passwords are harder to type in. And they don't help that much. It's better to allow people to use pass phrases.
2. Stop it with password expiration. That was an old idea for an old way we used computers. Today, don't make people change their passwords unless there's indication of compromise.
3. Let people use password managers. This is how we deal with all the passwords we need.
[0]: https://www.schneier.com/blog/archives/2017/10/changes_in_pass.html https://www.schneier.com/blog/archives/2017/10/changes_in_pa...
- trianglem 7y agoI agree with all of this except password managers. If you use a lot of different public computers or temporary work laptops they don’t always let you install LastPass, so I frequently ended up being unable to access my accounts.
- nickthegreek 7y agoI access my manager from my phone and type them in. I would never install my LastPass on a public computer even if they let me.
- Sohcahtoa82 7y agoAnd then you've got your phone open, displaying your password to shoulder surfers, for as long as it takes to type in your password.
- cbm-vic-20 7y agoI have a hard enough time typing 4mfkD.Q.27cC8,'@eG}a4{\* , I am very much not worried about a "shoulder surfer" either seeing the cleartext password on my tiny phone screen, or watching all of those keystrokes without me noticing them.
- naniwaduni 7y agoI'd be more concerned about it getting caught on camera.
- diamondo25 7y agoThey used to have a mobile page you could login to. It was really plain but it did what it did best: provide an easy and clean way to access your passwords when you are somewhere. It was something like https://lastpass.com/mobile https://lastpass.com/mobile ...
- fluidcruft 7y agoIt would be really cool if you could plug your phone in and it appeared as a USB keyboard device and you could "type" the password from the password manager that way without ever giving the computer access to anything except that password. Maybe some sort of simple USB dongle (like a yubikey) could be fed by the phone via bluetooth or nfc to do this?
- peteretep 7y agoIt would be even cooler if I could open an app on my phone, point it at a QR code on screen, and not have anything else bother me
- trillic 7y agoThis is (sorta) how SQRL works. https://www.grc.com/sqrl/sqrl.htm https://www.grc.com/sqrl/sqrl.htm
- fragmede 7y agoWhich, to be fair, is close to how it works inside Apple's walled garden. Logging into iCloud on a new computer will cause the iPhone attached to that account to pop-up a "confirm login" dialog, so the second factor for login is as unobtrusive as possible.
- tomp 7y agoNo you still need a password, which also makes it insecure on a public computer (where keyloggers might be installed). Instead, the better solution would be, you point your phone to a QR code on the computer screen, press “confirm”, the computer is magically logged in, until you then press “log out” on your phone and the computer is logged out.
- tatersolid 7y agoYou’ve just described SQRL
- 7y ago
- bashinator 7y agoIt would be even cooler if there were no possible vector for the computer to then compromise your phone, but I don't really see that happening.
- lostlogin 7y agoThat gets old very fast too though. Copying a long and complicated password manually is pretty grim.
- xmprt 7y agoPardon my ignorance but if you're worried about the computer being compromised so that they could somehow access your LastPass, why would you even use it for any authenticated work in the first place?
- toomuchtodo 7y agoFor scenarios like this, where the hardware is untrusted, Yubikey type devices are really the only solution (where the device can present as a user input device, and provide the necessary string secret). Everyone else can use a password manager. EDIT: If you're on an untrusted device, should you really be putting secrets into it? Maybe not!
- thenewnewguy 7y agoLastPass (like all other good online password managers) has a web UI.
- nirvdrum 7y agoI had an employer that blocked access to lastpass.com to discourage that sort of thing. I guess the idea is you shouldn't be using a work computer for personal stuff and you shouldn't put work passwords on a 3rd part site. In reality, things aren't split that cleanly, so the block was annoying.
- paxy 7y agoThat's an even bigger reason to use password managers. Use a mobile app and 2FA.
- all_blue_chucks 7y agoYou should never, ever, ever type a password on a public computer.
- spookthesunset 7y agoSo basically, you should never use public computers for anything beyond looking at YouTube anonymously?
- anon73044 7y agoAnd searching things that you can't search for at home or on your phone. The kinds of things that people get put on watchlist for, like where to buy industrial quantities of hydrofluoric acid.
- bashinator 7y agoUpvote. You have no way of knowing if that computer is compromised, say with bogus root SSL certificates to allow MitM of ostensibly secure web sites.
- iudqnolq 7y agoWhat if you store passwords for non-ssl sites in your password manager? I have passwords for some really old mailing lists that don't use SSL and had a big warning that they're completely insecure on the page. I especially don't want to use a shared password if it has a decent chance of being compromised, but if I cared if that account got compromised I wouldn't have set it up.
- n4r9 7y agoUse KeePass on a USB drive with a key file. You won't have to type a password or transmit anything over the internet.
- Aloha 7y agoWhich is why at a previous employer, everyone just stuffed all of it in a spreadsheet, with expiry dates, and last logged in times.
- iudqnolq 7y agoThat actually sounds pretty secure, if the computer had a reasonable password and FDE you've just implemented a hacky password manager. Even without FDE you're better than anyone who writes it down on a sticky or uses something trivial. Unless they're using Excel functions to generate password{n++} . That'd be clever and yet horrid at the same time.
- jankiehodgpodge 7y agoAlthough at most workplaces your documents are just a folder on a shared drive somewhere, which may not be secured well and in some cases not secured at all.
- Aloha 7y agoI used a little php script to do the password generation, and yes we did use FDE
- iudqnolq 7y agoIf the script is accessible to other people I suppose you have to worry about it being hacked, especially if you let php get out of date or take input in say password length?
- SlowRobotAhead 7y agoYou can use the Lastpass site on any computer without the browser extension.
- mint2 7y agoUnfortunately my company claims their credit card and electronic payment processing agreements require employee password to expire. If that’s actually true, then most companies hands are tied until those payment agencies update their requirements.
- sitharus 7y agoThis is true, PCI DSS still requires password expiry. The trick is figuring out the boundary of the systems that are subject to PCI.
- tatersolid 7y ago> This is true, PCI DSS still requires password expiry. We’ve been using a compensating control of “our password policy is exactly NIST SP 800-63B (2017) plus two more characters in Min length” for our PCI audits since the revision was published in 2017. It’s been accepted three times so far.
- cortesoft 7y agoAs always with PCI, it depends on your auditor.
- AmericanChopper 7y agoUsing NIST password guidelines as a compensating control has been accepted by every assessor I’ve dealt with (even the really bad ones). A compensating control must exceed the requirements of the control its compensating for, and the NIST rules clearly do. I’d say it has much more to do with how you write your compensating control worksheet rather than anything else. If you assessor is refusing to accept compensating controls, you should report them to the SSC, and then find a new assessor.
- tatersolid 7y agoYes, if you’re not actually doing the “compare password against breach lists” part of SP 800-63B regularly they likely won’t accept it. I hope forced expiry will be gone from next PCI revision anyway.
- jimnotgym 7y agoI totally agree that password expiry is a problem, however I have twice taken over AD based systems where there was widespread password sharing, and I found IT knew a lot of passwords of users. I found that a one off change didn't help, they all just updated each other. So my advice is to advise people that they will get resets. To run them through a couple with increasing complexity requirements. Then increase the period between resets dramatically without telling anyone, so 30 days (Still a novelty), 90 days (less fun), 120 days, 360 days. I suppose it is a password re-education exercise really. I always remind people that they are welcome to change their password whenever they want (then they will never see a forced reset). I also tell them that my single biggest requirement is that they don't use their Facebook password for work! I will keep password resets, but nothing like the 90 days PCI DSS still insists on. In legacy systems shared admin credentials are very common, and while working towards individual logins I tend to rotate these often, since a password manager can be used. It is hard to have individual accounts for everyone at an external support company for instance....
- guitarbill 7y agoWhile decreasing rotation frequency is definitely good, I'm not quite sure how is this supposed to help reuse? People will do what they need to to get their job done, exactly the finding of the article. Would be better to tackle the root cause by e.g. having shared, federated accounts or roles. Of course, it's easy to say, but should be worth it in the long run.
- rorykoehler 7y agoSurely the whole point of a password manager is to have a different long complex password for each system you login to without needing to remember any of them but your master password?
- TheSpiceIsLife 7y agoWhat part of the parent comment are you replying to?
- javajosh 7y agoI think he means that a password manager (PM) renders the other two points moot. Password expiry? No problem - my PM generates a new one easily. Complex rules? No problem - my PM will follow any rules you like. My response is that not everyone uses a PM, so the other two points are not moot. Also, FWIW, I find myself rather uneasy about using a PM, so the other two points aren't moot, at least for me. "One password to rule them all" means that you've created one nice big juicy target that needs to be breached once, versus a bunch of little targets that have to each be breached individually. To take one real-life example, if the TSA wants to rifle through your digital life, it will be much, much harder for them if you don't have a PM.
- mcny 7y agoSorry but I don’t understand how I’d use a password manager to unlock my computer. This password is for my active directory account and I hate that it expires every three months.
- input_sh 7y agoSo do I, and I manage the AD for my organization.
- tialaramex 7y agoTry to get the AD policy revised. Because there is (since 2017) clear NIST guidance saying not to do this, chances are that somewhere in your organisation a document can be updated to cite that NIST guidance and then the AD controls can be relaxed to let passwords have the same lifetime as the account they're for. Finding who owns this policy and getting them to fix it may take a bit longer than one of those 90 day password changes, but it'll feel like you made the world better and it may only take a phone call or an email to the right person. Newer Windows AD builds have FIDO2 support, so on shiny new computers you _could_ unlock "your" computer (one you've logged into recently) with a FIDO2 USB key, or a fingerprint reader. That's a much nicer way to unlock a computer you use all the time, while not discouraging you from using a nice long password that bad guys would need to guess or steal to get in from a different machine.
- rolltiide 7y agoThe one thing I really hate about IT security certifications is that they promulgate these ridiculous "best practices" Just come to the dark side and learn to program and privilege escalate. You'll learn all these practices and how to circumvent them.