4 ms·
Nothing stops them from using a unique passphrase. I am subjected to the same password requirements and use a unique passphrase every time. I see harvested pas
by discreditable 7y ago
Nothing stops them from using a unique passphrase. I am subjected to the same password requirements and use a unique passphrase every time.
I see harvested passwords as a larger threat than bruteforcing, so some kind of expiry is important. Some users might use good, unique passwords, but most will not.
- criddell 7y agoAre you saying NIST and Schneier are wrong about this?
- discreditable 7y agoSchneier says "don't make people change their passwords unless there's indication of compromise" I make the assumption that the longer a password exists, the more likely it's reused and compromised. I don't have insight into every password dump, but I know my users reuse passwords a lot. I think a long expiry is the best balance in my environment.
- acdha 7y agoThat’s not an indication of compromise: just you increasing the odds of people creating predictable passwords. If you’re concerned about dumps, setup one of the services which checks against HIBP for known-leaked passwords and then put all of your effort into MFA (especially FIDO) because that will stop the kind of attacks which are common in this century: immediate use of compromised credentials, high-skill phishing, etc.
- Sohcahtoa82 7y agoThe point though is that if password changes are required, even with a long expiration time, people are only going to make minor and probably predictable changes to their password. If if you did a 1-year password expiration, and last year's passwords were compromised, then if the attacker figures out that someone's password last year was "uwethskjv9j29#18", then there's a good chance that the attacker is going to try logging in with the password "uwethskjv9j29#19" this year and "uwethskjv9j29#20" next year, and will probably succeed. You gain nothing from password expiration, other than annoyed users and and even more annoyed IT team who has to deal with lockouts from people that changed their password to something secure.
- sjy 7y agoSurely you gain more than nothing, even if it's not enough to justify the costs imposed on your users? I often hear that attackers will simply increment the number at the end of your password, but users apply many different "simple" changes and it's likely that you'd need to try a fair few tries to guess correctly. That might be feasible if you have the new password hash or you're targeting an individual victim, but if you don't, then the password expiry policy offers some defence in depth.
- dragonwriter 7y ago> The point though is that if password changes are required, even with a long expiration time, people are only going to make minor and probably predictable changes to their password. More significantly, if changes are required or weird composition rules used, people are more likely to store their password in a convenient unprotected form (historically, often paper kept next to their main computer, which is a risk, but these days the convenient form may itself by subject to remote compromise, making an even bigger risk.)
- thiagomgd 7y agoif a password expires every year, people are just going to use P@ssword2018, P@ssword2019 and so on... You require new passwords every year, done Require symbols, done lower and uppercase, done numbers, done
- anon73044 7y agoWouldn't you rather be sure and run the passwords through JTR or HIBP? https://news.ycombinator.com/item?id=21204297 https://news.ycombinator.com/item?id=21204297
- deleted 7y ago[deleted]
- kevin_thibedeau 7y agoI frequently have perfectly adequate strong passwords rejected because it doesn't have the anointed mix of special characters, or more infuriating, has ASCII printable characters that aren't accepted, like caps, digits, or symbols. The latter systems are 100% guaranteed to be storing unhashed passwords.