5 ms·
God, i hate those "change your password at least every X days" policies. A good password does not become weak after some time.
by TimWolla 12y ago
God, i hate those "change your password at least every X days" policies. A good password does not become weak after some time.
- anExcitedBeast 12y agoNo, but people often use the same password for different services. Changing passwords regularly can cut off attacker access in the event of an undetected compromise.
- TimWolla 12y agoWell, those people would probably simple cycle through their passwords, or append an increasing counter. So regular changes do not protect the security, but annoys people that are using generated passwords that are completely unique for each and every service.
- UweSchmidt 12y agoIncreasing the counter at the end is obviously weak when you find that "password46" is not working anymore so you try "...47". However if someone steals a whole password database with a million passwords, chances are they just automate the login attempts and subsequent nefarious actions. They might not try to figure out anyone's naive password scheme if they get thousands of successful logins the easy way!? I'm saying this because I've heard your reasoning before, and of course I've been staring at the keyboard when trying to change one of my passwords, wondering just how clever I need to be right there.
- Liesmith 12y agoI disagree. I am always hearing about how this or that service got compromised and stored passwords in plaintext or something, and now all those passwords are in the wild. I write really hard to crack passwords (funny little poems I made up myself) and I still could get screwed because my bank stored it in an unsafe way, and now some russian dude knows my password is "I am so þirsty,5/but þe walls are unbroken.7/Where is Cool-Aid Man?5" Thus, I find myself writing new poems all the time. Which is actually great because they are fun to make and easy to remember. But yeah if I still used that one (something I wrote in 2008) I'd be screwed. There's no way that's safe now. What really drives me insane are services that limit the number of characters you can have for your password. Holy criminy that's dumb.
- deleted 12y ago[deleted]
- drzaiusapelord 12y agoSure it does. A lot of people re-use passwords with different services, so if one gets compromised, then criminals have that password. On top of it, people get compromised all the time. Its trivial for a virus to nab your saved browser passwords. Or someone sends you a phishing link and you happily type in your credentials. It looked official, right? All of this is invisible to the end user, typically. From the IT side of things these credentials are used for all sorts of things like authenticating with smtp to use our mail server to send spam, log into ftp sites to host malware, etc, etc. Then the end user angrily walks up to IT saying, "Everyone is saying my emails are spam. Why do you guys suck so much??!!" Forcing password rotation helps with this because there's a chance the password that got leaked is or will soon be retired. It also helps in scenarios when employees give their passwords out to other employees and then one of them gets fired and starts fucking with the system using someone else's credentials. In short, a lot of these polities exist because people are stupid. Don't blame those of us trying to mitigate the damage. That said, you don't need a 30 day expiration. I find 120-180 days works well enough. You don't need complexity turned on as much as you need a sane minimum length. I'd rather train people to use "mydogsnameisAlbert" than "Password1"
- cjensen 12y agoIf you rotate passwords every month, your users will be annoyed and use password that are either trivial, will write it down passwords, or have a trivial variation from month to month. In other words, they will resort to using less-secure passwords. The notion that rotating passwords improves security is little more than a cargo-cult.
- x1798DE 12y agoKeeping a password written down (in your wallet, in your desk, etc) is probably safer than you'd think, because people generally know how to secure physical items, but they're much less certain about how to secure digital information. I think it's obvious that expiring passwords increases security to some degree. It's also clear that user reactions will induce people to reduce the security of those passwords. The password expiry interval you choose (potentially as long as the duration of the system's existence) depends on your threat model, really. Security is hard and often application-specific.
- mey 12y ago30 days is a little aggressive but I do think a quarterly or ever 6 months is valid. Not all users behave appropriately with their passwords, allowing other people to use them, re-using them between systems or putting them on post-it notes under their keyboards. The rotation of the credential is simply a cheap but heavy handed way of dealing with those compromises to ensure the system returns over time to a default state of security and cuts out invalid access. Granted a better way to manage this is create good audit trails of how often, during what times and from where and what devices those credentials are used, but like I said it's a simple/cheap way of adding that layer of security.
- bluedino 12y agoYou have to stagger them in your environment. If you don't, you get flooded with password change/reset requests the first few days after a change has been forced.
- dubcanada 12y agoWhat I hate is systems that require you to 8 characters or longer lowercase uppercase number random symbol As far as I am concerned if I want to make my password jumping I should be able too, forcing someone to make a password they will never remember leads to several issues. 1. A password cracker knows exactly what to ignore which such requirements (obviously his 4 letter word dictionary is useless in this case). 2. People have trouble remembering them, so they typically write them down somewhere (a even bigger issue). 3. It's security through obscurity.