10 ms·
Can we get rid of the password expiration too? Requiring that users change their perfectly secure password every 6 months is absurd and gives the impression of
by kokonoko 1y ago
Can we get rid of the password expiration too? Requiring that users change their perfectly secure password every 6 months is absurd and gives the impression of security when in reality it only makes things worse.
- Geebs 1y agoOne hundred percent. I’d be interested to see how many people resort to having weaker passwords just to try to remember the new password every 6 months. I know many folks are proud of their password ‘system’ of using the same word and adding different numbers every time they need to change it. Not helpful.
- econ 1y agoIf the website gets one of those it works. If they get multiple example of the password systeem in action, how hard would it be to guess elsewhere? You might not even remember that you've used one variation before. I keep a long list of strong passwords and some 50 pins in my head, at least I think I do. I know a guy who regularly gets locked out of things. It's a terrifying process. Everything unravels.
- spjt 1y agoWhat usually happens to me is, I get stuck where whatever service I'm using insists the password must be changed RIGHT NOW before proceeding. There was something I was trying to do. Maybe I don't have a pen, I'm on my phone, whatever, I don't have time for this shit. I need to change it to something I will remember, which is something like "Password1". Maybe I remember to pick a better one later, maybe I don't. Maybe (looking at you, Okta) I can't change the password because I changed it too recently...
- brazzy 1y agoNIST only changed that recommendation last year. Expect that update to take at least 10 years to percolate through institutions like banks.
- GuB-42 1y agoThis recommendation dates back from 2017. > Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator. 8 years later, no one seems to care. Other things that the NIST doesn't recommend is rules such as "letters + numbers + special characters". What it does recommend is checking for known weak passwords, such as passwords that are present in dictionaries and leaks or relate to the user name. Here is the relevant document: https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html
- jermaustin1 1y agoAnd expect people to still implement it in the future, based on documentation from some consultancy that hasn't disseminated the new recommendation internally to their implementation engineers.
- signal11 1y agoBanks are aware that NIST and various other bodies have updated their guidance about password expiration. Even vendors like Microsoft who supply extensively to financial services, have updated their guidance about password policies. At this point — barring edge cases of operating in geographies where regulations haven’t caught up — it’s just inertia, aka “inaction doesn’t get you fired (usually)”.
- delfinom 1y agoIt's not inertia. In my big corpo's case, it's because the cybersecurity insurer is refusing to follow NIST.
- technion 1y agoI have been in three different organisations now with this same excuse, and actually called their insurer to clarify. In all cases, the insurer asks the password policy such as expirations. Complete absence of a written policy is a problem. Non expiring passwords was not. Someone in management took the application form and justified their own belief on security and two of those three companies still tell staff "it's because of our insurerer" even after given the facts.
- newhotelowner 1y agoOur hotel franchise requires us to change the password every month. We can't use the last 6-8 passwords.
- rrr_oh_man 1y agoPassword manager ftw
- pc86 1y agoThis is fine for services you can easily access on a phone or computer. My employer requires I change my laptop password every 60 days, it stores the last 2 years of passwords to prevent reuse. I am not opening up LastPass and plugging in a 32 character random string every time I want to start my computer up. My password at any given point is either a few random words and a number, or a short (8-12 character) alphanumeric string without symbols. But you know what it always is? On a post-it note stuck to the inside of my laptop. My employer is consciously choosing to make my laptop less secure because the CISO is an idiot.
- hamburglar 1y agoThe only solution to this problem is to put your password on a post-it note in the most obvious place possible? Are we sure the CISO is the idiot in this story? This sounds like malicious negligence. I sure hope nothing that actually matters is on your system.
- 9x39 1y agoWell, a TPM would eliminate this user-hostile auth dance, although that security model is different than a password. Failing to recognize and channel human behavior into positive behaviors and outcomes does suggest a level of ignorance/arrogance outside of extreme situations. There’s probably a type of data one might handle to justify physical access threat models, but incompetence and out of date knowledge from these types is far more likely. FWIW something like a third to half of CISO’s are from nontechnical management backgrounds, based on surveys I’ve seen.
- econ 1y agoIt indicates they are using good security practices that are no longer considered good. They might be living in 2010 which is worrying on its own.