3 ms·
I hate that HN users downvote concepts they disagree with. One can agree that rotation is good in theory and bad/annoying in practice (due to laziness). We can
by pontilanda 4y ago
I hate that HN users downvote concepts they disagree with.
One can agree that rotation is good in theory and bad/annoying in practice (due to laziness). We can only argue about how much of an impact it makes, but it certainly does not reduce the security.
We all deal with "password rotation" in real life and it's inescapable: credit cards expire. And to be fair I'm perfectly fine with that because I know a leak from 10 years ago can no longer affect me. I almost wish they expired earlier.
- josephcsible 4y ago> it certainly does not reduce the security. Yes it does. The more often you have to pick passwords, the more likely you are to pick weaker ones. > We all deal with "password rotation" in real life and it's inescapable: credit cards expire. And to be fair I'm perfectly fine with that because I know a leak from 10 years ago can no longer affect me. I almost wish they expired earlier. When a credit card is about to expire, doesn't the new one the bank sends you usually have the same number?
- pontilanda 4y ago> doesn't the new one the bank sends you usually have the same number? Never happened to me using several European banks. Either way the date and CVV change so that's part of the new password. > Yes it does. The more often you have to pick passwords, the more likely you are to pick weaker ones. I don’t think so. People will just change the number at the end, it's not like they will stop using aDgTGdE and start using 11111112 simply because of rotation. It's more likely that they will append a ! or change helloworld to helloworld2. It's not a downgrade by any mean. Plus such rotation even "guarantees" that the password isn't shared across services, unless they're all rotating with the same frequency and they all start with helloworld2
- Jon_Lowtek 4y ago> It's not a downgrade by any mean. If the minimum password length is 8 and the last two characters are the current month or year, the actual password length is roughly 6.