10 ms·
Forced password rotation and expiry seems the bigger problem; given that it causes people to get locked out so often, (e.g. if pw expires when on holiday), — of
by montebicyclelo 1y ago
Forced password rotation and expiry seems the bigger problem; given that it causes people to get locked out so often, (e.g. if pw expires when on holiday), — often then requiring travelling to IT, or at least a few hours trying to get IT on the phone to reset, or chasing up colleagues who aren't locked out to get in touch with IT.
Many (most?) companies still do it, despite it now not being recommended by NIST:
> Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)
https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html
Or by Microsoft
> Password expiration requirements do more harm than good...
https://learn.microsoft.com/en-us/microsoft-365/admin/misc/password-policy-recommendations?view=o365-worldwide https://learn.microsoft.com/en-us/microsoft-365/admin/misc/p...
But these don't seem to be authoritative enough for IT / security, (and there are still guidelines out there that do recommend the practice IIRC).
- throwaway843 1y ago1234abcd@ it is then for all my accounts.
- xp84 1y agoPassword rotation does nothing more than get you to use 1234abcd@ 1234abcd@1 1234abcd@2 1234abcd@3 I'm becoming pretty convinced that at least in the corporate space, we'd be way better off with a required 30 character minimum password, with the only rules being against gross repetition or sequences. (no a * 30 or abcd...yz1234567890 ). Teach people to use passphrases and work on absolutely minimizing the number of times people need to type it by use of SSO, passkeys, and password managers. Have them write it on a paper and keep it in a safe for when they forget it. This is a better use of the finite practical appetite for complying with policies than the idiotic "forcibly change it every 90 days" + "Your 8 character password needs to have at least one number, one uppercase, and one of these specific 8 characters: `! @ # $ % ^ & *`" By the way, to quote Old Biff Tannen, "oh, you don't have a safe. GET A SAFE!"
- kobieps 1y agoPreach. Gmail doesn't force password rotation, and one can just imagine the type of attacks they must sustain... Unfortunately corporate policies evolve at glacial speeds...
- Retric 1y agoI’m doubtful a 30 digit minimum password is a meaningful improvement over a 20 digit password here. Meanwhile actually typing in very long passwords adds up across a workday/year especially with mistakes.
- xp84 1y agoI think if done right, typing that password should be more like a once a quarter exception rather than a daily occurrence. Granted - there are blockers to getting there. IDK why for example, macOS can't use Touch ID from a cold boot, that's stupid, at least when there haven't been too many failed attempts or anything.
- Retric 1y agoTouch ID isn’t that secure. It’s fine for personal devices, but I wouldn’t trust it alone in a government or cooperate environment. A ~1:50,000 error rate per finger added sounds fine, but lose a few laptops and have multiple valid fingerprints etc and the odds quickly look significantly worse. Or a janitor could end up trying to log into a significant number of machines etc.
- zimpenfish 1y ago> macOS can't use Touch ID from a cold boot Isn't that because the Secure Enclave (the only place which contains the Touch ID biometric data) is locked by your password? "When a user's password is set up on an Apple Silicon Mac, the password is passed through a one-way hashing algorithm that produces a key used to encrypt the Secure enclave's key."[0] [0] https://blog.greggant.com/posts/2023/04/14/the-security-enclave-demystified.html https://blog.greggant.com/posts/2023/04/14/the-security-encl...
- 1y ago
- asveikau 1y agoSometimes when I log into a random website and I see a forced password reset, I wonder if it has been compromised, rather than setting a time-based expiry. If a site owner knows that certain accounts are part of a database breach or something, a reasonable step would be to force the users to change the password at next login.
- mooreds 1y agoAnother common reason to do a force password reset is if they've moved authentication providers and were not able to bring their hashes along. Some providers don't allow for hash export (Cognito, Entra).
- account42 1y agoOr just if they changed to a more secure hash algorithm themselves and want to upgrade users still on the older insecure one.
- RealStickman_ 1y agoThey could do that by comparing against the old hash and if it matches generate the new hash to store somewhere.
- blueflow 1y agoThis can be done at login time without the user noticing, as you have the plaintext password for a moment.
- mooreds 1y agoYeah, this is the best practice. We offer that in our product. But it's possible that you could follow the best practice and still force a reset. This could be because: * the customer or provider doesn't want to wait for everyone to log in * they've waited for N months and now there is a block of users who have not logged in yet and they think it is worth the user annoyance to just force them all to reset their password
- thousand_nights 1y agoif my password has not been leaked it's insane that providers think i should rotate it, but this still seems to be standard practice for some completely baffling reason
- dcow 1y agoThere’s weird math that says your password or generally a secret key is more secure if it’s existed for less time (generated fresh) because there hasn’t been as much time to brute force it. I don’t believe it but some hardcore types do.
- benlivengood 1y agoThat might apply to short passwords but passphrases are recommended and if they're >20 characters then brute forcing is not going to make meaningful progress toward them while we are all alive.
- fsckboy 1y ago>I don’t believe it but you have to believe it, it's true, you just think it's not the greatest threat or that the response to mitigate it (for example, using a pattern of temporary passwords to facilitate remembering them) would be worse than the disease.
- lurking_swe 1y agoif it causes 90% of people to just enter a simpler password, out of frustration and “fatigue”, then this is irrelevant IMO. Theory doesn’t take into account human behavior. It’s especially annoying when a company enforces these brain dead policies on employees. You want people to waste mental effort changing their passwords by 1 letter every 3 months, just to appease some IT manager? Give me a break lol. I’d rather have a long complex password that i remember and remember ONCE.
- eru 1y agoFor most people, writing (most of) their password on a piece of paper that they keep in their wallet would be pretty good security. Paper can't be hacked, and writing down the password allows for more complicated passwords. In case someone gets access to your wallet, you still keep a portion of the password not written down. (And if someone gets physical access to your stuff, you are hosed in general, because they can just install a keylogger. So even keeping your password fragment on a post-it under your keyboard would be fine-ish.)
- flerchin 1y agoLast time I brought this to our cyber folks, they pointed out that PCI standards require password rotation. So it depends upon which auditors you care about more.
- clwg 1y agoThis requirement is in section 8.3.9 of the PCI DSS[0], and only applies to single-factor authentication implementations, two-factor auth removes this requirement. [0] https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0_1.pdf https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard...
- throwaway72046 1y agoYour broker/bank still needs to do it, unfortunately... someone please fix this :( [0] https://www.finra.org/filing-reporting/entitlement/password-requirements https://www.finra.org/filing-reporting/entitlement/password-...
- dmoy 1y agoWhat's the scope of that? Not consumer accounts I imagine? I haven't had to change my bank account passwords in over a decade.
- Mtinie 1y ago> If the password length is 12 to 15 characters, it will be valid for 180 days > If the password length is 16 to 32 characters, it will be valid for 365 days Madness.
- lofties 1y agoI'm a big fan of "should not include profanity, words of a vulgar nature". It's not unthinkable my password manager comes up with a chain of letters that at one point will include "fuck".
- free652 1y agoJesus, it was so annoying so I kept appending a letter after each password reset -> a through z thankfully my current company let me keep my password for the last 3 years
- sakesun 1y agoPassword similarity rule was not enforced ?
- deleted 1y ago[deleted]
- lytedev 1y agoDoesn't enforcing this require storing the password in cleartext somewhere, which is a much more dangerous concept to begin with?
- eru 1y agoIn practice, that's probably how it's done. But in theory: no. Assume you keep the hashes of the last few passwords around. Then you can search in the 'neighbourhood' of the new password to check if any of this matches the old password's hash. By neighbourhood, I mean something like within a small edit-distance, where the kind of edits depend on what measure of similarity you want. If you only care about similarity to the last password (or care about that one specifically), then that's even easier: during the password change procedure you can have clear text access to both the old and the new passwords without storing them anywhere unhashed: because the user has just entered both passwords.
- SAI_Peregrinus 1y agoDoes anyone not add the year & month of the last password change to the end of their password? E.g. PascalCasePassphraseGoesHere2025-06, then at the next required change in (for example) 6 months: PascalCasePassphraseGoesHere2026-01. It almost certainly fits the inane "letter, number, and special character" requirements they probably have, complies with "different from your last X passwords", and is easy to keep track of the change interval. It also adds no security whatsoever! A user could almost certainly get away with Password2025-06, etc.
- repeekad 1y agoI’ve personally experienced the password change require that “more than X characters be different than the old password”
- valleyer 1y agoUm, that's a really bad sign...
- klysm 1y agoTo elaborate for the uninitiated, that means they are storing it in plaintext somewhere.
- mx_03 1y agoIs there any way to check that with non-plain-text password?
- jchw 1y agoActually it can be trivial as long as you can require the user to re-type the current password when entering a new password; check hash first, then check edit distance with the entered "current password" (and, of course, promptly throw it away once you know the edit distance.)
- mx_03 1y agoBad habits are hard to kill. Sometimes you just cant convince people that something is no longer recommended.
- viraptor 1y agoYou don't really need to convince people who implement it. You need to convince people creating certification/law, so PCI/SOC2/whatever. I'm still posting every time something like "for the record, I know we have to legally do this, but it's pointless and actually makes us less secure" for a few things.
- b0a04gl 1y ago[dead]
- brikym 1y agoI think a lot of people in IT know these things but having a 'strict' auth policy makes them seem competent so they just go with that. Besides there is not much incentive to make authentication efficient since the frustrated users are a captive audience not paying customers.
- SpaceNoodled 1y agoIt honestly forces me to keep a Post-It on my monitor with a hint to this season's new password suffix.
- olivermuty 1y agoMost SOC2 vendors still require rotation, it is unbelieveably frustrating.
- vrighter 1y agoStuff like ISO27001 still demands it. We have to rotate passwords, against modern cybersecurity practice, in order to comply with an information security standard.
- rjgray 1y agoISO 27001 doesn't say this. The control implementation guidance (ISO 27002) specifically cautions against requiring frequent password changes.
- qualeed 1y agoMost frameworks, at least most that I am aware of (north america) have removed password rotation requirements entirely, or have exemptions in place if you have MFA, use risk-based access policies, etc. Often when people say this, they are parroting their assessor. But not every assessor graduated at the top of their class, or cares to stay updated, or believes that they know better, etc.
- Xss3 1y agoHot take, password requirements are a necessity to prevent id10t errors. Another hot take, calling them passwords instead of pass phrases was a mistake. People have no problem making a secure pass phrase like 'apophis is coming in 2029’. It uses special chars and numbers, but some websites would reject it for spaces and some for being too long. I say these are hot takes despite aligning with NIST because I've never seen a company align with them.
- afiori 1y ago"password too long" for password shorter than a megabyte is the most idiotic error ever created. It only makes sense in HTTP basicauth and other system that keep plaintext passwords.
- efitz 1y agoI’ve always said “lockout turns a possible password guessing attack into a guaranteed denial-of-service attack”. Worse, it means that if an attacker can guess or otherwise obtain user names, the attacker needs nothing but network access to deny service to your users. My favorite example is the iOS policy where it added more and more time before the next login attempt was allowed; small children kept locking their parents out of iPads and iPhones for weeks or months.
- tzs 1y ago> Forced password rotation and expiry seems the bigger problem; given that it causes people to get locked out so often, (e.g. if pw expires when on holiday), — often then requiring travelling to IT, or at least a few hours trying to get IT on the phone to reset, or chasing up colleagues who aren't locked out to get in touch with IT. That is extremely annoying. On the other hand if I was a manager and that happened to someone I managed we'd definitely have a conversation where I would acknowledge that forced password rotation is idiotic, but also point out that our password expiration is 90 days after the most recent change, which is 12 weeks and 6 days, and ask how come they don't have a "deal with stupid password expiration" event on their calendar set to repeat every 11 weeks? That gives them 13 days warning. Vacations can be longer than 13 days, but I'd expect that when people are scheduling vacations they would check their calendar and make arrangements to deal with any events that occur when they won't be available. In this case dealing with it would mean changing the password before their vacation starts. I don't expect people to go all in on some fancy "Getting Things Done" or similar system, but surely it is not unreasonable to expect people to use a simple calendar for things like this?
- londons_explore 1y agoThe fact is that you might have an employee who is a real expert in 3rd century archaeology, but scheduling and password changes just aren't what they are here to do. They don't want to do it, don't know how to do it, and don't want to learn how to do it.
- tzs 1y agoSo when they accept an invitation to give a lecture six months from now on the discoveries at the Gudme Hall Complex in Denmark how do they arrange to make sure they will show up?
- chillfox 1y agoThe requirements usually don’t come from IT. It’s usually on the checklist for some audit that the organisation wants because it lowers insurance premiums or credit card processing fees. In some cases it’s because an executive believes it will be good evidence for them having done everything right in case of a breach. Point being the people implementing it usually know it’s a bad idea and so do the people asking for it. But politics and incentives are aligned with it being safer for the individuals to go along with it.
- ToucanLoucan 1y agoJust an unbreakable law of the universe. "Why did this stupid shit happen? Oh, it's money again."
- ajmurmann 1y agoIt's not money but inertia of very large systems. All these password changes cost money as well. If anything it's a market failure that insurance companies seem to have too little incentive to update their security requirements. This would likely be solved by reducing friction with both evaluating insurers in detail and switching between them.
- bunderbunder 1y agoIt's also a sort of moral hazard problem. If you, the person in charge of these decisions, allow an incumbent policy - even a bad one - to stand, then if something goes wrong you can blame the policy. If you change the policy, though, then you're at risk of being held personally responsible if something goes wrong. Even if the change isn't related to the problem. It's not just cybersecurity. I have a family member who was a medical director, and ran up against it whenever he wanted to update hospital policies and standards of care to reflect new findings. Legal would throw a shitfit about it every time. With the way tort law in the US works, the solution to the trolley problem is always "don't throw the switch" because as soon as you touch it you're involved and can be held responsible for what happens.
- lucideer 1y ago> But these don't seem to be authoritative enough for IT / security, As someone who's worked for a cybersecurity team that was responsible for enforcing password rotations in a company, trust me when I say that nobody was more eager to ditch the requirement than we were. This is enforced by external PCI auditors & nobody else. Fwiw, PCI DSS 4.0 has slightly relaxed this requirement by allowing companies to opt-out of password rotation if they meet a set of other criteria, but individuals employed as auditors tend to be stuck in their ways & have proved slow to adapt the 4.x changes when performing their reviews. They've tended to push for rotation rather than bothered to evaluate the extra criteria.
- BrandoElFollito 1y agoThese recommendations live in a mythical world, but not in a company. In a company, you have individual passwords known by many people. They are written here and there. They are passed to other orgs because something. In this ideal world of a non company, you have MFA everywhere, systems with great identity management wher you get bearers to access specific data, people using good passwords and whatnot. This is not true in a company. If this is true in yours, you are the lucky 1%, cheers (and I envy you). A good cybersecurity team will try to find reasonable solutions, a password rotation is one of them, in a despaired move to mitigate risks. And then you have trauma that will say "we cannot change the password because we don't know where it is used". Armchair cybersecurity experts should spend 24h with a company SOC to get an idea of the reality we live in.
- paradox460 1y agoIT seems to be a haven for minor dictators to enact their power fantasies
- ipython 1y agoI just had this argument with a state wide government website. I have to log in to this site maybe once per year to update contact information and update a few fields. Unfortunately, that site silently deactivates your account automatically every 90 days. So I'm forced to change the password literally every time I log into the dumb thing. They refused to establish MFA or passkeys - and instead insist that "NIST is the minimum recommendation for cybersecurity... and we take cybersecurity very seriously... to ensure the safety and security of the citizens... therefore we will not change our policy on mandatory account lockouts or password change requirements."
- inquirerGeneral 1y ago[dead]