4 ms·
My experience with not regularly changing passwords is that the security of your login credentials decays over time. If you keep track of when you changed your
by icu 5y ago
My experience with not regularly changing passwords is that the security of your login credentials decays over time. If you keep track of when you changed your passwords you will know what time period you were compromised if you check a website like https://haveibeenpwned.com https://haveibeenpwned.com.
If not, you'll might have to trust whatever PR says about when the breach occured.
I agree that strong passwords and cryptographic storage is the way to go, but I think you go too far when you say "users cannot be trusted with their own security" because some can. I think it really depends on who your users are.
- Jcowell 5y agoWhy does the time period matter when each credential should have a unique password anyways? Is knowing time of a breach important important when the only way you’ll know is through a website like the one you linked or when your credential is used unauthorized ? Also I personally think users absolutely cannot be trusted. At all. There should be a minimum viable security model for all users regardless of what their threat models should be. (I.e not allowing easily guessable passwords, enforcing a password over X length , forcing capitalized characters and symbols).
- bigiain 5y agoOne other thing to keep in mind, a lot of the time users (including me) couldn't give a fuck about the security of your website/webapp/mobileapp. If you force me to register an account to do what I need to do, and I'm never planning on returning anyway - you'll get my "default shit site password" and if you demand a deliverable email with confirmation, you'll get a throwaway-able email. I have a "spare" gmail account which I'll use with the "plus addressing" thing, so you'll likely get random-looking-string+sitename@gmail.com and the equivalent of Password123! - and I don't use that email for anything else. I'll filter mail with that +sitename to spam if/when it starts getting spam, since spammers know that trick and remove it - eventually I just throw away that gmail account and start a new one. Occasionally that bites me in the ass. Back when this stupid new "text messaging on the web" site started, you know, the one with the best and the fail whale, I was curious and set up an account (at least as much to squat my username as anything else). A few years later and I'm actually using and socialising there, late one night my account starts sending açai berry spam. Because my shit password was shit. (Luckly, they just send a half a dozen spam tweets, and didn't p0wn the account by changing the password/email on me...) One nice thing about password managers, at least you can search and find all the services you used a shitpassword on, and do an audit of whether you care enough to upgrade the password or delete that service's account.