5 ms·
The requirement to frequently change a perfectly good password is nonsense. https://pages.nist.gov/800-63-FAQ/#q-b05 https://pages.nist.gov/800-63-FAQ/#q-b05
by anonymousisme 5y ago
The requirement to frequently change a perfectly good password is nonsense.
https://pages.nist.gov/800-63-FAQ/#q-b05 https://pages.nist.gov/800-63-FAQ/#q-b05
It says:
SP 800-63B Section 5.1.1.2 paragraph 9 states:
“Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.”
Users tend to choose weaker memorized secrets when they know that they will have to change them in the near future. When those changes do occur, they often select a secret that is similar to their old memorized secret by applying a set of common transformations such as increasing a number in the password. This practice provides a false sense of security if any of the previous secrets has been compromised since attackers can apply these same common transformations. But if there is evidence that the memorized secret has been compromised, such as by a breach of the verifier’s hashed password database or observed fraudulent activity, subscribers should be required to change their memorized secrets. However, this event-based change should occur rarely, so that they are less motivated to choose a weak secret with the knowledge that it will only be used for a limited period of time.
- slownews45 5y ago"is nonsense" What a total lie. Do people actually work in / with govt who makes these statements? I just looked up a the current IRS checklist we've been forced to comply with which has driven lots of downline changes to all systems touching this system. "Control access to sensitive information by requiring employees to use “strong” passwords that *must be changed on a regular basis.". This is not an option, and regular has been defined as 90 days. A previous job (yes, I'm totally aware of NIST guidance) they forced a move to 30 days. 30 days with 12 character passwords is a joke and they blocked copy and paste. EVERY password was on sticky notes by computers after that. They are $100M system implementations. My point remains, the implementations of these things in the govt space is often the stuff of nightmares, and I have no idea who they are listening to for the money they spend.
- fouric 5y agoCan confirm, I have a friend who works as a federal agency employee (a different one than the IRS), and she constantly has to change her passwords - her agency DGAF about SP 800-63B Section 5.1.1.2 paragraph 9 (or, in fact, many of the other NIST password recommendations). GP comment is absolutely false.
- slownews45 5y agoWhat I don't get is we are getting NEW password rotation requirements on existing systems as part of the cyber protection pushes. We are way down the stack of course but just a basic approach like 1) Allow for cut and paste passwords 2) Reduce rotation requirements (even annually would be better). 3) 2FA if logging in from a new device (with no SMS) Would I'm sure get tons of protection without the insanity we have now. Some folks are asking for 16 character passwords but allow reset with a text message or email? Or a phone call to an overwhelmed help desk who barely verifies anything. That said, I've seen worse. I once tried to go as high as I could on the chain to get something even worse fixed (we were required to hand out a form for a program that had been out of existence for 5 years so form did nothing). They would not budge, I even got legal in on it. Because someone somewhere had ordered the form be distributed, the order had not been revoked, we still had to hand it out even though everyone agreed the form and program were no longer in existence. After I kept on escalating they threatened to prosecute or violate contract if form was not distributed an I kept pursuing the issue. So thousands of people filled out a form that just went no where.
- anonymousisme 5y agoPerhaps I should have been more clear. It is nonsense to require frequent password changes. NIST explains why in the above citation. It sucks that many USG organizations not only still enforce this, but require their contractors to do so as well.
- raffraffraff 5y agoI thought you were clear. Only after you got called a liar did I even notice the other meaning. Some people go online with a box of matches looking for things to set fire to.
- slownews45 5y agoAhh, fair point, but unfortunately many many agency security folks are still fixated on making it a requirement. Just doing it annually would be a big relief in some cases. 30 day rotations with no copy / paste is a nightmare.
- xenophonf 5y agoCan't speak to other agencies, but the one I work with enforces password changes every 180 days, with annual training and all related communications emphasizing the use of correct horse battery staple-style passphrases. It's been like this for a while now, several years at least.
- feoren 5y agoYou are both agreeing with each other.
- austhrow743 5y agoThey didn’t say it’s not required.
- anonymousisme 5y agoTrue. They say "SHOULD NOT" vs. "shall not", but since these are "guidelines" and not "requirements" I think they used the strongest language possible. (Note the capitalization in their FAQ. It's all caps!) Later in the same section, they use "SHALL" for requiring a password change after a known compromise.