8 ms·
Maybe I missed it, but I was surprised there was no mention of passwords. Mandatory password composition rules (excluding minimum length) and rotating password
by lobsang 2y ago
Maybe I missed it, but I was surprised there was no mention of passwords.
Mandatory password composition rules (excluding minimum length) and rotating passwords as well as all attempts at "replacing passwords" are inherintly dumb in my opinion.
The first have obvious consequences (people writing passwords down, choosing the same passwords, adding 1) leading to the second which have horrible / confusing UX (no I don't want to have my phone/random token generator on me any time I try to do something) and default to "passwords" anyway.
Please just let me choose a password of greater than X length containing or not containing any chachters I choose. That way I can actually remember it when I'm not using my phone/computer, in a foreign country, etc.
- belinder 2y agoMinimum length is dumb too because people just append 1 until it fits
- rekabis 2y agoI would love to see most drop-in/bolt-on authentication packages (such as DotNet’s Identity system) to adopt “bitwise complexity” as the only rule: not based on length or content, only the mathematical complexity of the bits used. KeePass uses this as an estimate of password “goodness”, and it’s altered my entire view of how appropriate any one password can be.
- Terr_ 2y agoIIRC the key point there is that it's contextual to whatever generation method scheme you used--or at least what method you told it was used--and it assumes the attacker knows the generation scheme. So "arugula" will score is very badly in the context of a passphrase of English words, but scores better as a (supposedly) random assortment of lowercase letters, etc.
- jamesfinlayson 2y agoI'm told that at work we're not allowed to have the same character appear three or more times consecutively in a password (I have never tried).
- hunter2_ 2y agoBut when someone tries to attack such a password, as long as whatever the user devised isn't represented by an entry in the attack dictionary, the attack strategy falls back to brute force, at which point a repetition scheme is irrelevant to attack time. Granted, if I were creating a repetitive password to meet a length requirement without high mental load, I'd repeat a more interesting part over and over, not a single character.
- borski 2y agoSure. But most people add “111111” or “123456” to the end. That’s why it’s on top of every password list.
- hunter2_ 2y agoIf cracking techniques catch the concatenation of those as suffixes to short undefined things, which I think many people would do at minimum, that would be worrisome indeed.
- NeoTar 2y agoUndisclosed minimum length is particularly egregious. It's very frustrating when you've got a secure system and you spend a few minutes thinking up a great, memorable, secure password; then realize that it's too few (or worse, too many!) characters. Even worse when the length requirements are incompatible with your password generation tool.
- fragmede 2y agoon the other hand, to gave us the password game, so there's that. https://neal.fun/password-game/ https://neal.fun/password-game/
- temporallobe 2y agoI’ve been preaching this message for many years now. For example, since password generators basically make keys that can’t be remembered, this has led to the advent of password managers, all protected by a single password, so your single point of failure is now just ONE password, the consequences of which would be that an attacker would have access to all of your passwords. The n-tries lockout rule is much more effective anyway, as it breaks the brute-force attack vector in most cases. I am not a cybersecurity expert, so perhaps there are cases where high-complexity, long passwords may make a difference. Not to mention MFA makes most of this moot anyway.
- nouveaux 2y agoMost of us can't remember more than one password. This means that if one site is compromised, then the attacker now has access to multiple sites. A password manager mitigates this issue.
- userbinator 2y agoVary the password per site based on your own algorithm.
- jay_kyburz 2y agoAKA, put the name of the site in the password :)
- userbinator 2y agoNot necessarily, but just a pattern that only you would likely remember.
- viraptor 2y agoYou need a pattern that only you recognise/understand, not just remember. It takes only one leak of your password from service FooBar that looks like "f....b" to know what to try on other sites. Patterns easy to remember are mostly easy to understand.
- raesene9 2y agoTBH where you see this kind of thing (mandatory periodic password rotation every month or two) being recommended, it's people not keeping up with even regulators view of good security practice. Both NIST in the US (https://pages.nist.gov/800-63-FAQ/ https://pages.nist.gov/800-63-FAQ/) and NCSC in the UK (https://www.ncsc.gov.uk/collection/passwords/updating-your-approach https://www.ncsc.gov.uk/collection/passwords/updating-your-a...) have quite decent guidance that doesn't have that kind of requirement.
- crngefest 2y agoWell, my experience working in the industry is that almost no company uses good security practices or goes beyond some outdated checklists - a huge number wants to rotate passwords, disallow/require special characters, lock out users after X attempts, or disallow users to choose a password they used previously (never understood that one). I think the number of orgs that follow best practices from NIST etc is pretty low.
- 8xeh 2y agoIt's not necessarily the organization's fault. In several companies that I've worked for (including government contractors) we are required to implement "certifications" of one kind or another to handle certain kinds of data, or to get some insurance, or to win some contract. There's nothing inherently wrong with that, but many of these require dubious "checkbox security" procedures and practices. Unfortunately, there's no point in arguing with an insurance company or a contract or a certification organization, certainly not when you're "just" the engineer, IT guy, or end user. There's also little point in arguing with your boss about it either. "Hey boss, this security requirement is pointless because of technical reason X and Y." Boss: "We have to do it to get the million dollar contract. Besides, more security is better, right? What's the problem?"
- funnybeam 2y agoI’ve had several companies, including cyber insurers, ask for specific password expiry policies and when I’ve gone back to them explaining that we don’t expire passwords and referencing the NCSC and NIST advice all of them have accepted that without any arguments. As you say, these are largely box ticking exercises but you don’t have to accept the limited options they give you as long as you can justify your position
- II2II 2y ago> Mandatory password composition rules (excluding minimum length) and rotating passwords as well as all attempts at "replacing passwords" are inherintly dumb in my opinion. I suspect that rotating passwords was a good idea at the time. There was some pretty poor security practices several decades ago, like sending passwords as clear text, which took decades to resolve. There are also people like to share passwords like candies. I'm not talking about sharing passwords to a streaming service you subscribe to, I'm talking about sharing access to critical resources with colleagues within an organization. I mean, it's still pretty bad which is why I disagree with them dismissing educating end users. Sure, some stuff can be resolved via technical means. They gave examples of that. Yet the social problems are rarely solvable via technical means (e.g. password sharing).
- Jerrrrrrry 2y ago>I suspect that rotating passwords was a good idea at the time. yes, when all password hashes were available to all users, and therefore had an expected bruteforce/expiration date. It is just another evolutionary artifact from a developing technology complexed with messy humans. Repeated truisms - especially in compsci, can be dangerous. NIST has finally understood that complex password requirements decrease security, because nobody is attacking the entrophy space - they are attacking the post-it note/notepad text file instead. This is actually a good example of an opposite case of Chesterton’s Fence https://fs.blog/chestertons-fence/ https://fs.blog/chestertons-fence/
- marshray 2y agoIt's not crazy to want a system to be designed such that it tends to converge to a secure state over time. We still have expiration dates on ID and credit cards and https certificates. The advantages just didn't outweigh the disadvantages in this scenario.
- Jerrrrrrry 2y agoApples to oranges. Usernames are public now. Back then, your username was public, and your password was assumed cracked/public, within a designated time-frame. Your analogy would hold if when your cert expires, everyone gets to spoof it consequence free.
- izacus 2y agoBased on the type of this rant - all security focused with little thought about usability of systems they're talking about - the author would probably be one of those people that mandate password rotation every week with minimum of 18 characters to "design systems safely by defatult". Oh, and prevent keyboards from working because they can infect computers via USB or something. (Yes, I'm commenting on the wierd idea about not allowing processes to run without asking - we're now learning from mobile OSes that this isn't practically feasible to build a universally useful OS that drove most of computer growth in the last 30 years).
- red_admiral 2y agoI was going to say passwords too ... but now I think passkeys would be a better candidate for dumbest ideas. For the average user, I expect they will cause no end of confusion.
- cqqxo4zV46cp 2y agoThat’s just recency bias.
- JJMcJ 2y ago> people writing passwords down Which is better, a strong password written down, or better yet stored a secured password manager, or a weak password committed to memory? As usual, XKCD has something to say about it: https://xkcd.com/936/ https://xkcd.com/936/
- uconnectlol 2y agoPassword policies are a joke since you use 5 websites and they will have 5 policies. 1. Bank etc will not allow special characters, because that's a "hacking attempt". So Firefox's password generator, for example, won't work. The user works around this by typing in suckmyDICK123!! and his password still never gets hacked because there usually isn't enough bruteforce throughput even with 1000 proxies or you'll just get your account locked forever once someone attempts to log into it 5 times and those 1000 IPs only get between 0.5-3 tries each with today's snakeoil appliances on the network. There's also the fact that most people already know that "bots will try your passwords at superhuman rate" by now. Then there's also the fact that not even one of these password policies stops users from choosing bad passwords. This is simply a case of "responsible" people trying and wasting tons of times to solve reality. These people who claim to know better than you have not even thought this out and have definitely not thought about much at all. 2. For everything that isn't your one or two sensitive things, like the bank, you want to use the same password. For example the 80 games you played for one minute that obnoxiously require making an account (for the bullshit non-game aspects of the game such as in game trading items). Most have custom GUIs too and you can't paste into them. You could use a password manager for these but why bother. You just use the same pass for all of them.
- ivlad 2y agoDear user with password “password11111111111” logging in from a random computer with two password stealers active, from a foreign country, and not willing to use MFA, incident response team will thank you and prepare a warm welcome when you are back to office. Honestly, this comment shows, that user education does not work.
- cuu508 2y ago> That way I can actually remember it when I'm not using my phone/computer, in a foreign country, etc. I'd be very wary of logging into accounts on any computer/phone other than my own.
- hot_gril 2y agoI don't get how it took until present day for randomly-generated asymmetric keys to become somewhat commonly used on the Web etc in the form of "passkeys" (confusing name btw). Password rotation and other rules never worked. Some sites still require a capital letter, number, and symbol, as if 99% of people aren't going to transform "cheese" -> "Cheese1!".