7 ms·
A couple of quick notes: 1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to
by random5634 6y ago
A couple of quick notes:
1) The OPM hack and now this all illustrate - if govt gives itself the big backdoors into everything, it's likely they will give it to russia, criminals, ex-boyfriends stalking ex-girlfriends etc.
2) My own impression of govt IT is largely security theatre in the area I was involved. In particular such massive complexity that agency staff think going around the rules is normal, because it's the only way to actually get work done. And then such glaring weaknesses that no one cares to fix. With google I've had one password for 20 years (my google account) which allows a hardware key for 2FA or google authenticator with what I imagine is sensible monitoring, new device authentication etc (I find this pretty secure).
Govt you are forced to write down these insanely long passwords with super complexity that cannot be cut and pasted that change very 30 or 60 days.
Because lost passwords are so common in these settings, the password reset process is usually a MASSIVE weakspot. I've seen it just be a phone call to a third party, you give them your username, they give you a new temp password - that's literally it. And the passwords end up everywhere. In lots of documents that float around, emailed around etc etc. And lots of password sharing when you get locked out of a tool and it will take a long time to get a new account setup (months). Pretty soon the procedures manual also gets you root access to everything.
- Jtsummers 6y agoThe insistence on the stupidly long passwords and 30-60 day expiration times created so many weaknesses. People choose obvious patterns for their passwords to get around it. Like `1q2w3e4r!Q@W#E$R`. Then they shift by one each time they have to update, by the time they get across the keyboard they can restart (or twice, in which case you swap the shift to the first half instead of second half). Or, this was fun, my first gov't job the guy had stored passwords on a sticky underneath the keyboard (I changed them all). They also used a shared account for admin stuffs, even though we were all given an admin token (like the smart card or CAC for regular login, but with admin credentials and issued separately). In theory, the DOD CAC system (they've gotten better over the years) eliminates the need for passwords entirely, but somehow most teams never tie their system to it properly.
- deleted 6y ago[deleted]
- Covzire 6y agoIndeed. Sports Team + Year, Season + Year, Company + Year or some other such combination should get you a good 10% or more of your users with only a few dozen permutations. They wrote 60 days into FEDRAMP I believe, something I jaw-droppingly realized last year sometime. Whoever is writing these policy frames don't know what they're doing. NIST did away with those periodic password change recommendations for a very good reason but IMO they need to now recommend the opposite, directly, because the constant password changes are doing real harm.
- throwaway894345 6y agoAccording to another comment, they do: > It's right there in section 5.1.1.2: "Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)." https://news.ycombinator.com/item?id=25421584 https://news.ycombinator.com/item?id=25421584
- markus_zhang 6y agoYeah I always use something + year + month + day, otherwise how am I supposed to get it around...
- vngzs 6y agoNIST no longer suggests such a rotation policy. They have accepted that it weakens security. Anecdotally, colleagues have successfully lobbied to drop (or not enforce) password expiration policies from other government bodies on the strength of this recommendation from NIST.
- Jtsummers 6y agoYeah, I know it's not actually recommended anymore, but the policy makers don't care. They're doing CYA policy. They do whatever seems to be the strongest possible thing, users and reality be damned. I was in a team whose security group eliminated the use of DVD drives for reading (not writing) data except for a few permitted individuals. Creating a massive chokepoint in every process where data had to come from off-network. Security didn't care, it took the realization of the cost (delays, people too busy moving data to do their actual jobs) for management to step in and end the nonsense. The same will be required for things like password policies. Until the issue becomes realized (weak/written passwords lead to a compromise), these policies will stay in place within organizations and teams. It doesn't help that the majority of the policy setters are not IT professionals (or only in the loosest sense, they can install software but have no real understanding of IT systems). In DoD, most come from a physical security background (retired/separated security forces).
- mcguire 6y agoAside from anything else, your second point is exactly spot-on. That's not just your impression.
- snarf21 6y agoSpot on, humans are always the weakest link. You must assume your users will invoke every worst practice imaginable and make your system secure anyway.
- kipchak 6y agoFor what it's worth NIST password guidance SP800-63b no longer advises the arbitrary expiration, so hopefully this is something that will change. >“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”
- GordonS 6y agoNIST changed those rules a few years ago, I think. I remember thinking "please, PLEASE let companies follow suit...". And still, very few have :(
- kipchak 6y agoI think it's new as of the 2019 revision, though it wouldn't surprise me if it's been ignored for a while. I don't think CMMC requirements specifically call out expiration periods, so hopefully a good sign. Microsoft seems to be fairly forward thinking[1] on passwords, doing away with expiration requirements and focusing more on their risk based MFA stuff. [1]https://www.microsoft.com/en-us/research/wp-content/uploads/2016/06/Microsoft_Password_Guidance-1.pdf https://www.microsoft.com/en-us/research/wp-content/uploads/...
- dlgeek 6y agoPCI/DSS hasn't yet, so that's holding up a lot of them.
- downtown_ 6y agoYou are allowed to use the NIST Guidance as a reason to change that to a longer timeframe. I have a couple of clients that are using 365days as of 2019.
- random5634 6y agoHas this shown up everywhere. Govt agencies still had it in contract docs. That might mean fedramp or PCI or some other standard still mandates it. Enforces minimum password complexity of case sensitivity, number of characters, mix of upper-case letters, lower-case letters, numbers, and special characters, including minimum requirements for each type; Enforces at least 5 changed characters when new passwords are created: Stores and transmits only cryptographically-protected passwords; Enforces password minimum and maximum lifetime restrictions of 60 days; Prohibits password reuse for 10 generations ...
- all_blue_chucks 6y agoNeither of these hacks involved "back doors" as they are normally defined. One was an authentication bypass; the other was a supply chain attack. Neither involved any sort of deliberate covert access mechanism.
- hamburglar 6y agoI don't think OP meant to imply that backdoors had anything to do with this. It's meant to underscore the argument against backdooring encryption by pointing out that when you trust some entity with a backdoor, you're potentially opening that backdoor to anyone who can break that entity's security, which may be very, very flawed.
- all_blue_chucks 6y agoThat's unrelated to backdoors (deliberate covert access mechanisms). All parties with access to data, regardless of whether it is via a backdoor, can put that data at risk due to their own security.
- hamburglar 6y agoThis is only unrelated if you don't consider government-mandated master key escrow a "backdoor," which seems deliberately obtuse to me. Regardless, the OP's point was that this is an additional argument against governments mandating a way to access your encrypted data, because you shouldn't be compelled to trust anyone else with a "don't worry, only we will have access" sort of system.
- random5634 6y agoLet me be cystal clear. I've worked in domestic violence. Cops will use various tools to stalk their ex'es despite your claims that back door or priveleged access will not be abused. Jump over to healthcare, the worker with full access to the govt it system for cases WILL lookup their friend / family members / neighbors / famous person if they see them on site or realize they are in system. I have one experience with a private health HMO. A close relative, senior doctor, absolutely knew they would be immediately fired if they looked up family records. It was crazy, they would not do ANYTHING related to family stuff even by request of person involved. Obviously this place had some type of audit trail, some type of monitoring team for non-assigned patient record lookups etc. My govt IT job, to do billing you had to be able to see case notes, and the system was integrated across of a ton of agencies, so everyone basically had access to everything and because you had to share logins and passwords (it took like 6 months to get a new account setup) there wasn't any accountability (not that I think they monitored anyway). I came away very unimpressed. We had to use outdated IE / Java combos etc. as well and block all system updates. The default landing page was an unregistered domain name.
- textech 6y agoIncompetence runs through every facet of American government, corporations and even private businesses. There's an insane amount of bureaucracy and people doing IT who have no business doing IT. As for the corporations, the established ones get taken over by the MBA types who have no clue about software or security nor do they care as long as the numbers look good for the next quarter.
- dcolkitt 6y agoI'd bet dollars to donuts that firms run by professional managers almost certainly have better security practices than family or founder run firms. I say this because research shows that professionally managed firms excel in virtually every other facet of operations and management[1]. [1] https://hbr.org/2011/03/family-firms-need-professional https://hbr.org/2011/03/family-firms-need-professional
- khamba 6y agoAlthough I do not disagree with your comment, I would do a double take befpre accepting the source you cite because they are very much incentived to proclaim the result they proclaim.
- x0x0 6y agoMBAs discover companies desperately need MBAs!
- textech 6y agoyou mean professionally run corporations like Equifax, Target or SolarWinds (published ftp password to github)?
- Aperocky 6y agoProfessionally managed versus family managed. Not surprising, both are not quite related to the technical matter being discussed. Muskets beat bows and arrows, but we're in the 21st century now.
- SystemOut 6y agoI hated this part of being on-call for government customers. I had to go through some crazy adjudication process all for the privilege of having to change my passwords every 60 days. And even though I used a password manager for them I couldn't paste them in because the VM I was required to use to access the systems didn't allow pasting from the outside. So I just typed them into notes on the VM and left them there.
- at-fates-hands 6y ago>> In lots of documents that float around, emailed around etc etc. The amount of fortune 500 and fortune 100 companies that I worked at where this is commonplace is staggering. The amount of businesses that never change their passwords is quite frankly, shocking. I left a fortune 500 company two years ago and I just tried my login on their external facing portal - and it still worked. I've seen passwords being passed around in word docs and internal blog posts. At one place they were mixing development information with financial information. The idea you had several folders of corporate contracts mingling with developer docs on a sharepoint server was a real eye opener for me. Nobody else seemed to care when I brought up the fact you just gave a bunch of developers access to facebook contracts and other financially important docs they have no reason to have access to. Their reason? It was too hard to set up a new folder with access restricted. After a few years of experiencing these, I just became kind of apathetic to it. If nobody in authority cares, then why should I??
- Eduard 6y ago> With google I've had one password for 20 years (my google account) which allows a hardware key for 2FA or google authenticator with what I imagine is sensible monitoring, new device authentication etc (I find this pretty secure). I too hope this is not just security theater as well.
- mNovak 6y agoYou should check out the new CMMC requirements -- basically a new set of basic cyber security requirements for all DoD suppliers, starting next year. It's heavily based on the NIST guidelines, so strong on 2FA, and discourages arbitrary password rotation.
- wslack 6y agoUS gov guidance from NIST no longer suggests regular password resets, but that guidance hasn't gotten out yet. > Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator. Source: https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html