5 ms·
> Microsoft employee Aaron Margosis said the requirement is an “ancient and obsolete mitigation of very low value.” That kind of magical thinking is what got u
by ben509 5y ago
> Microsoft employee Aaron Margosis said the requirement is an “ancient and obsolete mitigation of very low value.”
That kind of magical thinking is what got us mandatory password rotation in the first place.
Password rotation has a kernel of truth: automated credential rotation really works, and sometimes you need to force manual rotations to migrate to a newer hash algorithm, and I'll bring up another reason for it.
But the main reason we have password rotation is people have some magical belief that a credential gets "old" so we have to freshen it up.
Security rules are the same: they work, or they don't, and that can be very complicated due to human factors. But they don't "get old" and magically lose their effectiveness. If password rotation is broken, it's always been broken.
> Chief among them, the requirements encourage end users to choose weaker passwords than they otherwise would. A password that had been “P@$$w0rd1” becomes “P@$$w0rd2” and so on.
Not true. If they hadn't been forced to rotate, they would have stuck with P@$$w0rd1 the whole time, and P@$$w0rd2 is not weaker than that.
> At the same time, the mandatory changes provide little security benefit, since passwords should be changed immediately in the event of a real breach rather than after a set amount of time prescribed by a policy.
There is a clear benefit, especially for large enterprise systems: a periodic password change does put a limit on when the attacker could have used the password.
So when a credential is exploited, if you're rotating yearly, you only need to search back at most a year to figure out the scope of the breach.
I don't know how much of a benefit this is, in practice. Maybe someone who has done a real log dive can comment.
The only certainty is that you must never have passwords older than logs.
> If it’s a given that a password is likely to be stolen, how many days is an acceptable length of time to continue to allow the thief to use that stolen password?
They get this right.
- dredmorbius 5y agoRotating (or required change) on some circumstantial criterion (the old password is know or suspected to be compromised, system update, etc.) is entirely valid. Forced scheduled frequent password updates are not and worsen rather than improve security. That's the point here. In environments in which data leakage probability is high, and detection capabilities poor, periodic password changes are a defensible risk-mitigation measure, though in practice unless new tokens are themselves robust, the practice backfires. The problem is that both sides of the risk calculus need to be considered --- compromised token validity period, and token strength. People being people, the first is actually the safer risk to take.
- aflag 5y ago> Not true. If they hadn't been forced to rotate, they would have stuck with P@$$w0rd1 the whole time, and P@$$w0rd2 is not weaker than that. The thing is that with the requirement you can guess the last one or two characters of pretty much the entire user base. Also, if you’re constantly changing your password it possibly means that people have to type it in more often, which can lead to shorter passwords too.