4 ms·
Do people even actually change their passwords when there is no need to do so, just because the password is old?
by Cr0s 5y ago
Do people even actually change their passwords when there is no need to do so, just because the password is old?
- daneel_w 5y agoFor certain sensitive websites (e.g. domain registrar) I change passwords once a year or so, because there's really no guarantee that administration would 1) notice a breach early or at all, 2) fully understand the scope/severity, or 3) even notify their users about a breach.
- Flozzin 5y agoI update my passwords from time to time. I don't trust the organizations will always say if there is breach, know there is a breach, or actually know how far and wide a breach went.
- m12k 5y agoDo you trust them to salt and hash your password using bcrypt? (rather than store it in plain text). Do you use a password manager to generate strong passwords that are at least 16 chars long? If you can answer yes to both, then it doesn't actually matter if your hashed password was part of a breach or not, the hackers won't be able to brute force it. (Of course if hackers manage to steal the private key with which your session cookie is encrypted, they can still log in as you - but then changing your password won't help either).
- Cr0s 5y agoThis seems reasonable. How often do you change you passwords? Feels like it would get extremely tedious if you have more then a few accounts though, no?
- Flozzin 5y agoThis only applies to banking and email passwords. And most last over a year. I don't have a schedule, just one morning I wake up and go, 'oh yea, I've been using that password since 2019...'.
- woliveirajr 5y agoYes. For sites, desktops, everything that have some rule stating that passwords expires after 30/90/180 days, must not repeat the last 3/5/10 passwords, must have at minimum/maximum n characters, must/must not contain special symbols or some subset of it.
- dagw 5y ago3 of the last 4 places I've worked had as policy that you must change your password every 6 month.
- tarellel 5y agoMy current work forces updates every 3 months. It seems more like a security issue requiring this reset so often. This is because they create another problem when anyone you talk to will say they have their password and just increment a number for every password change. That way they’re not having to remember a whole new password every few months. So there’s never much of a change in anyones password during these rotations. - abcde1 - abcde2 - abcde3 - …
- pc86 5y agoI think this is an issue for things like a system login where you can't necessarily use 1Password or your equivalent. I have my work domain password in 1Password, and it's a huge pain in the ass when I need to use it in that context. However, if you use a password manager, and have access to it, I think forcing key rotation on a short schedule actually increases security. The downside of course being that most people don't use a password manager, and most people use the same relatively unsecure password for everything.
- nend 5y agoThis has been a standard IT policy for companies in the US for like 20 years. Probably 3/4 of the companies I've worked at over that time anyway.
- kasey_junk 5y agoI think the question is do people naturally change old passwords without such policies. The policies are the problem and the industry has recognized it so they’ve moved away from those recommendations.
- Cr0s 5y agoYes, this basically. Sure if you have to change your password you will, but if there is nothing compelling you to do so why do it? And if yes, why.
- ryangittins 5y agoNIST actually changed their recommendation relatively recently and no longer suggests periodic password changes without reason. > Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator. Source: https://pages.nist.gov/800-63-3/sp800-63b.html#memsecretver https://pages.nist.gov/800-63-3/sp800-63b.html#memsecretver
- _wldu 5y agoYes, and I believe they initially made this change in June 2017 (almost 5 years ago now). IT audit/compliance is typically 5 to 10 years behind best security practices and some standards are even slower to catch up.
- ryangittins 5y agoWelp, I guess I am now old enough that 5 years ago "relatively recently." :/
- rcMgD2BwE72F 5y agoYes. You can set your passwords to expire after a date (or a period) in KeePassXC. They will show up in your Health Check reports along with weak or non-unique passwords, possible leaks and more https://keepassxc.org/blog/2020-08-15-keepassxc-password-healthcheck/ https://keepassxc.org/blog/2020-08-15-keepassxc-password-hea...