17 ms·
There’s no need to change passwords if they're robust, unique and not breached
- Cr0s 5y agoDo people even actually change their passwords when there is no need to do so, just because the password is old?
- daneel_w 5y agoFor certain sensitive websites (e.g. domain registrar) I change passwords once a year or so, because there's really no guarantee that administration would 1) notice a breach early or at all, 2) fully understand the scope/severity, or 3) even notify their users about a breach.
- Flozzin 5y agoI update my passwords from time to time. I don't trust the organizations will always say if there is breach, know there is a breach, or actually know how far and wide a breach went.
- m12k 5y agoDo you trust them to salt and hash your password using bcrypt? (rather than store it in plain text). Do you use a password manager to generate strong passwords that are at least 16 chars long? If you can answer yes to both, then it doesn't actually matter if your hashed password was part of a breach or not, the hackers won't be able to brute force it. (Of course if hackers manage to steal the private key with which your session cookie is encrypted, they can still log in as you - but then changing your password won't help either).
- Cr0s 5y agoThis seems reasonable. How often do you change you passwords? Feels like it would get extremely tedious if you have more then a few accounts though, no?
- Flozzin 5y agoThis only applies to banking and email passwords. And most last over a year. I don't have a schedule, just one morning I wake up and go, 'oh yea, I've been using that password since 2019...'.
- woliveirajr 5y agoYes. For sites, desktops, everything that have some rule stating that passwords expires after 30/90/180 days, must not repeat the last 3/5/10 passwords, must have at minimum/maximum n characters, must/must not contain special symbols or some subset of it.
- dagw 5y ago3 of the last 4 places I've worked had as policy that you must change your password every 6 month.
- tarellel 5y agoMy current work forces updates every 3 months. It seems more like a security issue requiring this reset so often. This is because they create another problem when anyone you talk to will say they have their password and just increment a number for every password change. That way they’re not having to remember a whole new password every few months. So there’s never much of a change in anyones password during these rotations. - abcde1 - abcde2 - abcde3 - …
- pc86 5y agoI think this is an issue for things like a system login where you can't necessarily use 1Password or your equivalent. I have my work domain password in 1Password, and it's a huge pain in the ass when I need to use it in that context. However, if you use a password manager, and have access to it, I think forcing key rotation on a short schedule actually increases security. The downside of course being that most people don't use a password manager, and most people use the same relatively unsecure password for everything.
- nend 5y agoThis has been a standard IT policy for companies in the US for like 20 years. Probably 3/4 of the companies I've worked at over that time anyway.
- kasey_junk 5y agoI think the question is do people naturally change old passwords without such policies. The policies are the problem and the industry has recognized it so they’ve moved away from those recommendations.
- Cr0s 5y agoYes, this basically. Sure if you have to change your password you will, but if there is nothing compelling you to do so why do it? And if yes, why.
- ryangittins 5y agoNIST actually changed their recommendation relatively recently and no longer suggests periodic password changes without reason. > Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator. Source: https://pages.nist.gov/800-63-3/sp800-63b.html#memsecretver https://pages.nist.gov/800-63-3/sp800-63b.html#memsecretver
- _wldu 5y agoYes, and I believe they initially made this change in June 2017 (almost 5 years ago now). IT audit/compliance is typically 5 to 10 years behind best security practices and some standards are even slower to catch up.
- ryangittins 5y agoWelp, I guess I am now old enough that 5 years ago "relatively recently." :/
- rcMgD2BwE72F 5y agoYes. You can set your passwords to expire after a date (or a period) in KeePassXC. They will show up in your Health Check reports along with weak or non-unique passwords, possible leaks and more https://keepassxc.org/blog/2020-08-15-keepassxc-password-healthcheck/ https://keepassxc.org/blog/2020-08-15-keepassxc-password-hea...
- colinclerk 5y agoPerhaps surprisingly, US government guidelines exist, are pretty fantastic, and agree with the author: Memorized secrets SHALL be at least 8 characters in length if chosen by the subscriber. Memorized secrets chosen randomly by the CSP or verifier SHALL be at least 6 characters in length and MAY be entirely numeric. If the CSP or verifier disallows a chosen memorized secret based on its appearance on a blacklist of compromised values, the subscriber SHALL be required to choose a different memorized secret. No other complexity requirements for memorized secrets SHOULD be imposed. It's called NIST 800 63-B and available here: https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html Shameless plug - I'm the cofounder of Clerk and we handle passwords in a sane way out-of-the-box: https://clerk.dev/features/passwords https://clerk.dev/features/passwords
- deleted 5y ago[deleted]
- 6LLvveMx2koXfwn 5y ago6 characters in length seems a bit shoddy.
- wccrawford 5y agoYeah, bump that to 8 and it's more reasonable. And if it's already required to be randomly chosen, why not 10?
- deleted 5y ago[deleted]
- xboxnolifes 5y agoIt's not 10 because it still needs to be memorized.
- bombcar 5y agoThat’s the key people are missing. There’s a trade-off (though people can easily memorize phone numbers for example) when the password gets to complicated and you have to write it down.
- andrey_utkin 5y agoI am unconvinced. What about persistent password bruteforcing? Rate limits? OK, bruteforcing is happening within those rate limits. That's how the password rots - it becomes less of a secret as many values are tried. Key material rotation seems to be a sensible practice in general.
- whoomp12342 5y agoif your password is strong, this negates bruteforcing, unless if there is a good reason someone would want to hack you.
- q3k 5y agoWith a ratelimit of 60 attempts per minute (which is significantly higher than any user would legitimately ever need) you're looking at thousands of years to bruteforce a random 6 character alphanumeric password.
- new_guy 5y agoThis seems remarkably unintuitive, but the math checks out. (26+10)⁶ = 2,176,782,336 1,450 minutes a day 2,176,782,336 / (1,450 * 60) = ~25,000 years
- tejohnso 5y agoYou went from min per day multiplied by constant per min and ended up with years somehow.
- q3k 5y agoMy reasoning: Number of 6-character alphanumeric passwords: (2*26+10)**6 == 56800235584 Number of seconds in a year: 60*60*24*365 == 31536000 Number of years to enumerate all 6-character alphanumeric passwords at one password a second: >>> ((2*26+10)**6)/(60*60*24*365) 1801.1236549974633 (this assumes that alphanumeric is [a-zA-Z0-9], which some might disagree with)
- 5y ago
- whoomp12342 5y agoThere is no need for passwords. Cant we figure out something better? its only been like 50 years.
- awestroke 5y agoGo ahead and suggest an alternative
- rubyist5eva 5y agoOne-time use magic links sent to a verified email.
- OJFord 5y agoI hate that. (At least allow a password instead.)
- seanw444 5y agoYeah it's an obnoxious process. I don't know why people are so against passwords. Use a manager (or at least something like Lesspass), and then you're fine. Passwords aren't scary. They won't bite.
- manigandham 5y agoToo many extra steps, especially on mobile. And very suspectable to phishing and social engineering. Also makes it impossible to login if you lose email access (and what if you need to change your address because of it?)
- jandrese 5y agoYou just Chicken and Egged your email login.
- suifbwish 5y agoI am very curious why public private key auth is not a thing for websites and applications. I would rather have a single password to the server that publicly hosts my public key then I can simply point websites and applications to that address during signup. Every app/site would check the server every 5-20 mins for changes to my public key in case I need to change it. Then I can use my private key to authenticate to all these sites/apps instead of trying to keep track of 500 damn passwords.
- ejb999 5y agoI am in the camp of requiring people to have strong passwords, and not requiring them to be changed - ever. When you ask people to remember too many passwords, they start writing them down and/or forgetting them, which leads to other problems. My oldest online account - btw it is a brokerage account at one of the big brokerage houses, where a great deal of my cash and investments sit - has not asked me to change the password in close to 25 years, which I find quite funny.
- chimeracoder 5y ago> When you ask people to remember too many passwords, they start writing them down and/or forgetting them, which leads to other problems. Writing passwords down isn't the worst thing. If you can't convince someone to use a password manager like 1Password, getting them to use a physical notebook of unique and strong passwords is actually the next best thing, because (combined with 2FA) it protects them against the most relevant threat models for most people (phishing and password stuffing).
- falcolas 5y agoA business card stored in a wallet or purse is pretty good too. After all, we're already pretty used to protecting our credit cards, identity cards, and cash.
- Brian_K_White 5y agoIt's pretty bad to put both a debit card and it's password together. The only reason it's even tolerable risk to walk around out in the wide random world with a debit or credit card on your person all day every day, is because somewhere else you have the means to disable it and declare it lost. This is like storing the keys to your car conveniently right on your car.
- sj4nz 5y agoIf anything it should be the "red herring" password that locks the account if retried too many times.
- e1g 5y agoIn the USA, the latest government guidance from Jan 2022 is that "Password policies MUST NOT require use of special characters or regular rotation". [1] This is a strong upgrade from earlier softer language like "don't have to/should not". In practice, this new rule contradicts almost every InfoSec stance out there, but all government agencies must comply with this new rule by the end of the year, so expect lots of conversations and changes. [1] https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-09.pdf https://www.whitehouse.gov/wp-content/uploads/2022/01/M-22-0... Approachable summary at https://www.bastionzero.com/blog/i-read-the-federal-governments-zero-trust-memo-so-you-dont-have-to https://www.bastionzero.com/blog/i-read-the-federal-governme...
- the_snooze 5y agoThe "character class" requirement really doesn't add much security. And the "password rotation" policy can actually result in worse passwords than otherwise. Those measures were effectively just folk medicine from the days when the threat was thought to be someone manually trying to brute-force your password at your terminal.
- falcolas 5y ago> can actually result in worse passwords than otherwise Does actually. I still require some of the password "rotation" schemes folks would use when we were forced to change them monthly (not a typo, sadly): 1qaz2wsx -> 2wsx3edc -> 3edc4rfv... Pass1word -> Pass2word -> Pass3word...
- kps 5y ago“February, 2022” Upper case, lower case, digit, special character, does not match any previous password, changeable monthly without having to write it down…
- bachmeier 5y ago> The "character class" requirement really doesn't add much security. If you're generating your passwords randomly (using a password manager) it actually reduces security because it reduces the set of acceptable passwords.
- Moodles 5y agoA lot of users will simply change their passwords by appending a 1, 2, 3, etc. at the end. Presumably if old passwords did sour and become compromised then Hashcat would easily crack the minor tweak on the new password. To be fair to these companies, the reason they do passwords so terribly is because of such poor guidance and standards in the past. Even now NIST has SP 800-132 for guidance on generating a cryptographic key from a password for storage applications, which is different and often confused with guidance on storing passwords (which they don’t give advice for). There they say to use PBKDF. Also, compliance standards such as PCI don’t allow for modern storage like Argon2, so at best companies use something like bcrypt.
- bombcar 5y agoThis is the main thing. A password leak either gets the password or gives you a basis for attacking variations of it.
- Karsteski 5y agoThis is literally what I did at my last company, where we had to change our passwords every few weeks. It was so damn frustrating. I'd be fine memorizing a random string of text, but having to constantly change my passwords meant that I'd continuously get locked out until I did that. For my own personal use, I just use a password manager + randomly generated passwords, but it seems corporations are so damn slow to pick up on these obviously beneficial things that they choose clearly antiquated standards instead.
- jrodthree24 5y agoMy company just fixed this. By requiring you to change your password by more than the last character. Really cutting edge security here.
- orthecreedence 5y ago2password 3password 4password ... >=]
- 5y ago
- blable2 5y agoAgree. Further, I'm getting sick of the forced requirements for them.
- skbdpup 5y ago> Unless there’s a security breach where it’s stored These can go undetected. Imagine 1. Hacker dumps database with your username & password in it 2. Brute-forces the database offline 3. Logs in as you / Sells it to 3rd party that logs in as you A lot of time can pass between these steps. Changing your password is a mitigation against this scenario.
- sascha_sl 5y agoAlso, bad practices like logging passwords can be unearthed and fixed without any indication in between the times you change your password.
- tialaramex 5y agoThe correct mitigation for these scenarios, which I agree are a problem, is to not use shared secrets. Key rotation/ changing your password is a poor workaround. If you steal the WebAuthn database from my toy implementation, now, or tomorrow or ten years in the past, it makes no difference because it doesn't have any secrets in it, so, you don't learn anything useful. "Man, if I was this web site, which I'm not, now I could validate that the authentication was successful". In such schemes the only thing similar to a "secret" is the Private Key, which exists only briefly temporarily inside my Security Key or other authenticator when it is doing its thing.
- UltraViolence 5y agoI use Password Safe, an open-source password database. I highly recommend it for people that are more computer savvy. For the digital illiterates OnePass may be more suitable.
- seanw444 5y agoKeePassXC is also a great open-source password manager.
- timbit42 5y agoI've used both and KeePassXC is clunkier, requiring more clicks to get your un/pw. PasswordSafe was designed by Bruce Schneier.
- pkilgore 5y ago"digital illiterates" is quite a take there when any password manager is involved.
- UltraViolence 5y agoThat's why Firefox added password generation on my request. I'm the person that you should thank for that, I believe.
- netheril96 5y agoWe should advocate for two step authentication everywhere, so a password leak alone cannot give the attacker access.
- wintermutestwin 5y agoI imagine a world where governments get together and mandate that all online passwords use the same standard of password requirements and salt/hashing at the backend. Penalty should be 10% of your gross revenue. While they are at it mandate some standards of customer service if your business exceeds $1M in gross revenue (must have a "get human" button and the call hold time shall not exceed 15 minutes). I know that sounds like a fantasy utopia, but I remember a time in the 70s when there was a serious push for consumer advocacy in the US.
- ReactiveJelly 5y agoAnd that customer service MUST NOT accept "I just typed some random words" as the answer to a """security""" question.
- jasonpeacock 5y agoWe effectively have this now with PCI-DSS (requirements imposed by credit-card processing companies), and it sucks because of the bureaucracy involved in making any change. It has take literally over a decade to relax the requirement for password rotation from 3mo to 1yr for employee accounts of companies that process CC payments, despite industry knowledge and formal studies saying that frequent password rotation was detrimental and useless. Instead of defining the process, state the outcome you want and set penalties on failing to meet the outcome. E.g. "don't have password leaks, or it will cost $1k per account paid directly to the account holder" (or your percent of gross, split among leaked accounts). Let companies implement those controls however they wish, as long as they are achieving the outcome and penalties are actually being applied. I agree that failures need to have significant penalties, otherwise companies will decide that the penalty costs less than the prevention (which is true today) and minimize their investment in security.
- adam0c 5y ago#PREACH! the Hive infograpgh (amongst others) always comes to mind; 18 characters long, upper, lower, numerical, special. estimate time to brute force 438tn years.
- ReactiveJelly 5y agoHow many years to memorize and type 18 random characters?
- clsec 5y agonot OP but I only have to remember two 18 character passwords, my laptop and KeepassXC. I use all of OP's suggestions as well as mixing languages, one being an indigenous language that only about 20K people in the world know, together with a little leet speak. I haven't been breached since the early 2000's.
- macintux 5y agoI suggested my co-workers, at least half-seriously, that upon mandatory password change the old password should be added to an internal website. That seems like a good way to ensure people don’t use stupid passwords: public embarrassment.
- simonbarker87 5y agoFor people who have to change their password regularly I suggest just adding the month and year in numbers at the end of whatever password they like to use. That way there is a clue in the current month and year as to what their password probably is should they forget
- harryvederci 5y agoIf a hacker found an old password of yours, the month an year would be a pretty easy indictor of what to try next, right?
- rgoulter 5y agoIt's a trade-off of convenience vs security. If you're worried a password will leak, how frequently should you rotate it to maintain security? e.g. Even rotating yearly still seems a chore if you do it for websites you don't frequently visit (such as sites you made 1 order from). The "add YYMMDD" or whatever is a way of working around a policy which automatically enforces a more frequent rotation than you want.
- KMnO4 5y agoMy security policy is based on the most common data breaches, where an adversary obtains a big list of email/passwords and just tries them on a handful of sites (Facebook, Twitter, etc), throwing out the records that don't work. Sure, it's technically possible to decipher the algorithm[0] I use to generate new passwords, but that's not what I'm protecting against. If someone is trying to attack a specific person, there are much more effective ways[1]. [0]: For example, if my password for HN is "1y2c3o4m5b!$", you could sit down and figure out my reddit password. [1]: https://gizmodo.com/how-i-lost-my-50-000-twitter-username-1511578384 https://gizmodo.com/how-i-lost-my-50-000-twitter-username-15...
- simonbarker87 5y agoOh yeh it’s not ideal but the alternative is my relatives having a post-it note nearby with their current password written down - I feel this is a lesser of two evils
- brightball 5y agoWhenever I talk to people about security, I give a simple thought experiment: Assume the passwords for all of your users are public. Doesn't matter how it happened. How are your users protected? The moment that people go down this road of thought everything gets a lot better. 1. How do you restore accounts that may have been taken over? 2. How do you detect logins that look like normal behavior vs those that don't? 3. Is a password alone enough to get them in? If you address those 3 things everything gets A LOT easier for you and your users.
- cromd 5y agoWorth keeping in mind that passwords do actually leak. Companies have had incidents where they were inadvertently logging secrets passed to them. I've also typed/pasted secrets in the wrong field, which can get into some database or user-interface tracking tool. I've typed my sudo password instead of a vpn password at the command line, thinking sudo login had triggered when it was instead cached. Who knows when these crumbs might turn up. And as others pointed out, breaches aren't always known or disclosed. Is it too late if you change your password 6 months after it's compromised? Not sure - maybe people sit on their exploits sometimes, or wait for a better buyer, or sell secrets in small batches. All that said, I've never changed a password when it was newer than 5 years old, and only do it for crucial services, but if I were a bigger target, I might do it more.
- dylan604 5y agoIf you do not reuse passwords and one of them does leak, then the only thing affected is the site/service that was compromised. Hence the word "unique" in the title.
- cromd 5y agoThat is true, but that one secret is still at risk, and maybe that secret means the world to you. You don't know when the info will be discovered or change hands. "No need to change" could maybe be nitpicked even though I agree with it in general - changing seems to provide some marginal probabilistic benefit if done properly, and the cost/benefit probably depends on what you are protecting.
- hyperman1 5y agoScenario: Your device has a keylogger. It already happened that e.g. android device makers were overly aggressive in debug logging almost everything, including everything you type or paste on the clipboard. Leaking a password on your side is an unknown unknown, so password rotation is not a bad practice on its own for a security conscious person: It limits a leak in time. Mandatory password rotation is a whole different kettle of fish, as it pushes users to lower password quality. Infosec policy was required to balance 2 conflicting needs, and the past has thougt us we balanced wrong.
- rasengan 5y agoThis headline is going to put bad information in the minds of those who don’t read articles and comments.
- amtamt 5y agoWhat about an undetected data breach leaking username and passwords? Periodic password replacement reduces the window where someone's stolen password is used a long time after breach. This may not be the threat scenario for every type of accounts, but in some type it would one among the most important ones.
- jaywalk 5y agoIf it remains undetected, the rotated passwords will still be leaking. Once you detect and mitigate it, you force everyone to reset their password immediately. Periodic password rotation is pointless.
- voakbasda 5y agoOne problem with this strategy is that you never know if there has been a leak. Proactively changing passwords protects against such leakage, such that the leaked password must be used within the window where it is still valid.
- Brian_K_White 5y agoOne missed point, the advice is even slightly better than they argue, since they only argue that it's not necessary to change it, which is just an argument of convenience. But updating a password is itself an attack surface. More so than merely using it to log in. It's one of the times where an attacker may be tricking you into giving it to them, either by a fake page or app dialog, or in concert with maybe they have a way to receive the verification email or text. Also it's a less frequent operation, meaning it's easier to fake. You are more likely to notice any tiny discrepency and detect a fake in the way your normal login screen looks than some account management screen. Basically updating a password is a riskier action than the normal daily use of the same password. And that alone is it's own even stronger argument for avoiding doing it unnecessarily.
- detinho 5y agoIndeed. Recently my wife updated her google account password thinking she was updating the password from the game she wanted to play. She only knew because I'm on the recovery password list and as soon I received the email from Google asked her to confirm.
- snarf21 5y agoAgreed. I think the main new vector is a "new device". So having the user approve on an old device (where possible or otherwise use 2FA) would prevent most of the log in attacks. It also removes the attack of "look under the mouse pad" where bribing a cleaning person gets you a whole company's user logins.
- majkinetor 5y agoOr key logger
- jmyeet 5y agoI hate password rotation rules. Companies have iT departments that love nothing more than to add "value" by adding their own spin on what password security should be. It's pure security theater. At every company I've ever worked that required password rotation, everyone just incremented a digit, usually at the end. I also hate the completely arbitrary rules on length (I mean, why do some sites have a maximum length?). Some require uppercase and lowercase as well as digits and certain special characters and what special characters are allowed is inconsistent and completely arbitrary. We need to focus on how much entropy [1] a password has without arbitrary rules. 20 lowercase letters is going to be better than a 7 letter dictionary word with one letter capitalized and a number of symbol on the end. In fact pretty much every password 8 characters of length should be considered cracked. 10 should probably be the absolute minimum. [1]: https://xkcd.com/936/ https://xkcd.com/936/
- DigitallyFidget 5y agoI use parts of song lyrics or movie quotes for most my passwords, and I do the same with increasing a digit. I'm at digit change 17. The thing that REALLY kills me is when a password has a maximum length.
- thejerz 5y ago> There’s no need to change passwords if they're robust, unique and not breached This assumes you'll know if passwords were exposed in a breach. Some breaches go undetected.
- dylan604 5y agoAnother comment that reads as if they are skipping the "unique" part of the text they are quoting. If you use unique passwords for everything and a leak goes undetected, the damage is contained to just that one site/service. cherry picking quotes to nitpick is only effective if you address the full quote rather than cherry picking a point of a cherry picked quote
- spicybright 5y agoIt's honestly strange this has to be said as it's such an obvious thing.
- jandrese 5y agoThis also assumes that changing the password would effectively lock out attackers that have already breached your systems.
- spicybright 5y agoIt's vastly more likely you'll be pwned by remote passwords than local programs. Even if it is a local program, there's so many ways to store a password there's no automated way to reliably get a password. Your threat model will become a person targeting you specifically, thumbing through your files to find information, etc.
- 0xbadcafebee 5y agoSo, really, you should change a password regularly if: - The password is weak - It is ever reused - Anyone else has access to it - You use it on a device you don't control - You use it on a device which might be running malware and can intercept it - It was stored insecurely
- PopAlongKid 5y ago>Anyone else has access to it While sharing passwords is never a good idea, sometimes it is necessary. For example, I am the treasurer of a non-profit organization, an elected position that rotates every two years. We have a savings account at a credit union that for a variety of reasons requires online access by multiple individuals who change over time. The only way to keep this even a little secure over time is to require a password change every time someone drops off the authorized access list. There could also be software licensing issues that lead to multiple users sharing a login for software, same thing applies.
- ozim 5y agoThat is totally reasonable scheme if amount of people with access is restricted to something like 5 and you always know when someone drops off.
- itvision 5y agoI've been saying this for years. Whoever came up with the idea that passwords need to be regularly changed must be shot because no one has ever proved it makes any sense. What it actually does is that people write passwords everywhere (papers, text files, etc), thus actually lowering their security.
- mgerdts 5y agoPasswords and password files are better protected now than they were 25+ years ago. - ssh did not exist or was not widely used. People used telnet, ftp, rlogin, etc. which put plaintext passwords on the wire. - UNIX systems that used NIS distributed the password file to clients via a plaintext map which could be obtained by anyone with “ypcat passwd”. Many passwords were guessed in seconds using crack or John the ripper. Complex passwords would withstand those attacks for weeks or months with those tools using a single computer to reverse them. - (I think) NTLM and CIFS authentication put password hashes over the wire. Various tools were available to reverse these as well. Once it was feasible to build rainbow tables, getting a password from a hash was a simple lookup. - switched networks were not widely used making sniffing passwords or hashes from the wire much easier. Hubs would broadcast all traffic from all ports to the other ports on the hub. Coaxial Ethernet daisy chained many computers along the same physical wire. I think that “ring” networks (token ring, fddi) also passed all traffic by all nodes. In those days, regular password changes were important because your password it it’s hash was regularly exposed. I’d argue that today, any password you type where someone else may have a camera should be treated as though it has also been compromised. This means that if your password manager isn’t auto filling it, you should be using that password only with two factor authentication. (edit: formatting, auto-carrot)
- zacharycohn 5y agoI encourage everyone in a position to run into this discussion internally to memorize a few key sections of NIST 800-63. It's come in handy more than once...
- cies 5y ago> not breached Which a consumer of a service does not know. There's law now to force providers of services to announce leaks/breaches and there's haveibeenpwned; both are no guarantee. Changing a password gives consumers a fresh start. > Passwords do not age. They do not sour, spoil, or stale. The "fresh start" does imply some sort of spoiling/ageing. Rotating passwords (re-freshing) in the age of password managers is not that much work, for some critical accounts that may be a good thing.
- tinalumfoil 5y agoYou won't necessarily know about every leak. If a security camera records you typing in your password (or you accidentally hit view password in your manager) today someone might find that recording and access your account two years from now. Resetting your password resets the buildup of these small information leaks that occur over time. Best practices get better over time. Maybe two years ago that password was stored as an MD5 hash, and that hash was getting leaked to log data. Bank.com has since fixed that problem, but you don't get the benefit unless you change your password.
- Beached 5y agoI feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of them) I have worked at within the last 10 years, the IAM team has already implimented, or was working on implimenting a system that removed regular rotation, special chars and number requirements, and relied on three things: Length, a dictionary check at the time of pass creation, and routine dictionary attacks against the credential store. This started 10 years ago, for someone to make the same claims now, is not a shock. Please note that if you are unable to impliment such an IAM system, especially the inability to dictionary check the credentials against known lists (seclists' github is great for this), then length plus regular rotation is still the recommendation
- sdoering 5y agoWorking at a acquisition of a big consulting corporation. Had these recommendations in place before being acquired. We're onboarded onto better security systems by new mothership. Password rotation every 75 days. No dictionary check. No check against known breached passwords. No real reasonable rules against insecure passwords (like ac_Paul2022 is valid 'secure' password). Additional massive "spyware" on corporate devices in the name of security. I don't care about security since being 'on system'. I don't do anything private on these devices. So I couldn't care less about what mothership does with their spy-/securityware on said machine. I couldn't care less about the security. I cared when I could do something about security. When I had control about the security on the device. But why should I nowadays care.
- Spivak 5y agoI think my cynical take is to not actually care. Very few people in the whole security industry actually bother to care because it's mostly box checking regulatory requirements and/or certifications because security beyond the absolute minimum just isn't important to the job. Most places aren't being attacked or broken into, and in the slim chance it happens there's less money to say "sorry for being breached, we're $worthless_cert compliant, nothing else we could do" because customers will believe it.
- explaingarlic 5y ago> Robust, unique and not breached What? If they're not breached then that invalidates the other two points anyway - unless you can find an authentication endpoint that doesn't rate limit. HTTP proxies are expensive and trying to brute force something that is on-server is not a common attack vector. I know its nit-picking, but the title is incendiary and warrants that.
- dahart 5y ago> some organizations want to convince us that with the passage of time your password becomes increasingly susceptible to attack I feel like this is somewhat true for self-fulfilling prophecy reasons; these same organizations don’t always disclose every compromise or leak of their systems, and don’t always force a password reset when it happens because it would reveal they’ve been hacked. I’m certain I have multiple online accounts at organizations that have suffered minor, major, and ransomware level breaches.
- ouid 5y agoDoesn't everyone just log in to everything with the forgot password link?
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- 1970-01-01 5y agoHere's a good and free tip: A unique password breach can be turned around to better know your enemy. Set-up a canary honeypot and monitor your environment for it: See https://github.com/thinkst/opencanary https://github.com/thinkst/opencanary
- the_arun 5y ago> Unless there’s a security breach where it’s stored But how confidentally we know this. Hence, people periodically change password. Or am I missing something?
- the_snooze 5y agoThere are better mechanisms than password rotation to mitigate (even undetected) security breaches. Password databases can and should be storing that data using proper hashing functions like Argon or bcrypt. Those are designed to be slow, so brute-forcing them even offline and in parallel becomes time-consuming. This increases the time between when a breach happens and when those passwords become useful to attackers. This gives the service more opportunity to detect the breach and force users to reset their passwords. If attackers somehow obtain actual passwords before then, then the login system should be using risk-based authentication, where it throws additional challenges if the user appears to be logging in from a completely unexpected IP address or client.
- ahmed_ds 5y agoI think organisations forcing people to change passwords causes greater security risks. For example - if you have a bunch password character and length requirement, you will find people writing their passwords on paper or being more flexible in storing them. Because of this frequency, people will forget their password often and require assistance of IT admins or other people often through phones and emails. I would say, strong password is slowly becoming a myth due to organizations failing understand what it is before creating a policy surrounding it.
- cpuguy83 5y ago"And not breached" is the key there. Passwords are breached all the time, usually without notification. See services like 1Passwords Watchtower, or look manually at lists like haveibeenpwned.
- borplk 5y agoThere is still a specific case for password rotation which is to periodically rule out the threat of compromised passwords. Meaning, if your password is 10 years old it's subject to any leaks or security events during that long time frame. If it's 3 months old, anything that could have happened to it must have happened in the last 3 months which is much better than 10 years.
- teknopaul 5y agoOne thing people seem to forget is that if passwords are long and too complicated to be remembered then thave to be written down somewhere, a password manager is all your eggs in one basket. Lose access to your password manager and you can't access any online accounts with unrememberable passwords. Depending on the use case, a rememberable password is often a better option. One you can easily type on a phone is often a priority. My WiFi passwords are long lowercase no spaces word combinations, that are grammatically incorrect. Easy to remember and type on phones or WiFi printers. Most websites won't allow that. I find sites that ignore my opinion on password security annoying. Some sites I just don't use because of their password policy.
- nu11ptr 5y agoCan someone please forward this to my IT security team? :-)
- Zamicol 5y agoA problem of passwords is how do you know when a password has been breached? The beauty of public key authentication is that there's nothing to breach on one side.
- solatic 5y agoPossibly contrarian point of view: a) Passwords should be easily rememberable. Pick four words are string them together (e.g. correcthorsebatterystaple). b) You must have a physical security key to authenticate - a Yubikey etc. If those two factors are not enough, then forget working from home / mobile authentication - require people to arrive in-person and work in-person, with network restrictions on top of the two-factor authentication. If two-factor authentication isn't enough, and IP address restrictions aren't of help to enforce know-your-user when they show up in person, then I swear, God help you. At that point, you're no longer practicing security, you're practicing paranoia.
- khalby786 5y ago>network restrictions on top of the two -factor authentication That is exactly what I thought was the case too until I recently entered the code Google Authenticator gave me although my mobile was not connected to the internet. And it worked.
- solatic 5y agoIf you can even reach the login screen, in spite of a network control that's supposed to exist, then your network controls aren't working. TOTP is supposed to work without a network connection.
- mooreds 5y agoThe tldr of this post: What Should You Do? There’s a simple checklist of improvements you can make to keep your passwords forever secret: If you aren’t already, start using a password manager. Use the password manager to generate strong, unique passwords for every account. Review old accounts that contain personal, proprietary, or financial information and update their passwords using the password manager. Never share personal facts, like your pet’s name, when required. Instead, replace a real fact with random text that you store in your password manager for later access. Enable two-factor authentication wherever available. I can't argue with any of this! But there are obstacles on the path to this utopia. Password managers are becoming more and more usable for average folks, though I've seen some confusion in some of my non-tech friends/family, esp when integrated into browsers. There's also the question of market penetration. Is your grandma going to use a password manager? Other trends I've seen: Passwordless auth tying into WebAuthN. If a site can tie into a method secured by the OS, all the better. I'm not sure the uptake, but have seen some presentations/comments about it being a far superior UX. Also, seen some startups built (and raising $$$) around just this. Known, trusted bigcos like Facebook (ya, I know, but they are trusted by lots of non tech folks) and Google. This has some upsides because they can secure accounts really well, and also keep on top of new security reqs like MFA. But there're plenty of HN stories about being locked out of these IdPs, so this may be a bit of a scary delegation for some. Passwordless auth tied to email. This is great for low value, infrequently used accounts because often 'send me creds via email' is the default path anyway, usually via 'forgot password' flows.
- redbar0n 5y agoHow do you know if the password has been breached? More than not, you don’t. Hence, change password rutinely. That’s the logic, I presume.
- bborud 5y agoYou don't; except in a very limited sense if you use tools that check your passwords regularly against password leaks. But that still doesn't mean forced regular password rotation makes you safer. Changing your password is in itself a relatively high risk activity. And the likelihood of your password leaking tends to be dependent on factors you control. For instance, if you assume that a given service provider won't leak their password database (which is usually hashed in some way), you are being optimistic. You should always expect that this can happen and act accordingly when choosing, or preferably generating, a new password.
- redbar0n 5y ago> And the likelihood of your password leaking tends to be dependent on factors you control. Do you mean if you reuse the same password(s)? > But that still doesn't mean forced regular password rotation makes you safer. Would you say that even for people who use a password mamager and generate their passwords?
- rdiddly 5y agoThis is good for developers but there are two important unknowns if you're an end user: 1) You don't know whether the service or site employs best practices e.g. throttling. (Although you might be able to test that yourself if you're tech savvy.) So you may have to assume the worst, and there goes Point 1. 2) You can't be sure they will report a breach if it occurs, or that the password will ever show up in e.g. haveibeenpwned. So there goes Point 3. Point 2, you do have control over.
- noasaservice 5y agoIt's all right there in NIST 800-63-3 https://pages.nist.gov/800-63-3/sp800-63-3.html https://pages.nist.gov/800-63-3/sp800-63-3.html Big takeaways: Longer passwords. No hard requirement of symbols. Passwords don't change unless its in breach notifications online Regular scanning of breaches for hacked login/passwords or commonly used passwords
- Havoc 5y ago>and not breached Bit of an ideal conditions assumption. If security isn’t breached then you by definition don’t have a security issue
- ozim 5y agoThat is why changing password gained popularity, one has to assume password was breached. You might never know if operator lost your pw.
- thenoblesunfish 5y agoI’m not sure that this article sufficiently addresses the following natural objection: I don’t always know when my password has been leaked, and the chance of it having been leaked increases with time, so I should change my passwords ( to new strong, unique values) to lower the chance that they’re compromised.
- jandrese 5y agoIMHO almost all organizations have terrible password policies. There are only a few requirements for a good password: 1. The password must be difficult to the point of impossible for a computer to guess. 2. The password must be memorable enough that a person can create it once and then remember it a month later. If you don't satisfy requirement #1 then it will be hacked with a GPU farm. If you don't satisfy requirement #2 then the users will undermine your security in a multitude of ways. Almost no corporate password policy attempts to address or even facilitate option #2. They don't even mention it! Many corporate password policies are actively hostile to option #2, requiring a bunch of stuff that's hard for people to remember but only reduce the search space for the computer farms attacking your leaked password database. I like to use phrases made of things that sound like words, but aren't in the dictionary. Make them themed to be memorable. I call them Jabberwocky passwords. Were it not in famous poem a good password would be "mimsy were the Borogroves".
- asimops 5y agoWhile it is certainly correct to never enforce changing a password, I would argue that it is totally okay to expire it in certain scenarios. When my company set up the Active Directory f.e. we put a LSA password filter[0] in place that checks against HIBP. The password policy was set to expire every 90 days, atleast 15 characters and dont enforce a history. The non existent history was clearly communicated and users are encouraged to just enter their existing password three times when it expires. That way there is only one place where the passwords are checked for leaks and they are already there in plain, so it is manageable and doesn't add that much attack surface. [0]: Something like https://github.com/fblz/PassFilter https://github.com/fblz/PassFilter or https://github.com/rlabolle/hibppwdflt https://github.com/rlabolle/hibppwdflt
- olliej 5y agoEven NIST has stopped recommending password rotation, so it’s irksome that there are still organisations that require it.
- alasdair_ 5y agoAssuming a single character has something in the order of 100 possible values (I.e. a US English keyboard, no Unicode etc.) then a 12 character random password would take about 11.5 days to crack if you had a billion machines that could each crack a billion passwords a second. Assuming NTLM hashes you can currently crack almost 100 billion hashes per second on a single AWS p3.16xlarge that costs $25/hour to run (https://www.thesecurityfactory.be/password-cracking-speed/ https://www.thesecurityfactory.be/password-cracking-speed/) I.e. you’d need 10 million hours of these machines to try every combination possible, with an average time to crack of 5 million hours. I.e. a total cost of $125 million, although I bet you could negotiate a pretty good AWS discount and/ or build the servers yourself and optimize them for cracking, so let’s call it around $50 million to crack a truly random 12-ASCII character password today. Assuming Moore’s law improvements and improvements in energy costs/ efficiency and we can reasonably assume this cost could roughly halve every 18 months, to under $1 million in a decade. That’s not a lot of money to a nation state actor, so if you’re in a position where you seriously worry about active attacks against you specifically, perhaps using passwords that are longer than 12 characters is worthwhile.
- MaulingMonkey 5y agoAnd when do you know that said passwords have been breached? Companies RMA, sell off, donate, and/or dispose of older drives, RAID caches, computers, workstations - are you 100% sure everything was DBANed properly without any data still lurking in bad sectors? All it takes is one snoopy fellow dumpster diving, or going through the garage-saled hardware of your former IT guy who made backups, finding some hardcoded credentials on an unencrypted or poorly encrypted drive - or other similar act of stupidity - to potentially leverage mistakes made years ago into active network access. As annoying as I find password rotation, I get it.
- mrtweetyhack 5y ago
- snow_mac 5y agoIsThisAGoodPassword2022?
- farzher 5y agopasswords get leaked more than cracked. this article is dumb