Password expiration is dead, long live passwords
techcrunch.com
Password expiration is dead, long live passwords
1–10 of 316 posts
Re: Password expiration is dead, long live passwords
#2Re: Password expiration is dead, long live passwords
#3Re: Password expiration is dead, long live passwords
#4Good riddance to password expiration.
Re: Password expiration is dead, long live passwords
#5I'm not entirely sure that I'd agree with this mentality. Sure, at a glance it sounds good. If the password has been safeguarded, there's really not much reason to force expiration. However, wouldn't the age of the password reduce the security of it by default? The longer a password exists for, the more likely it is that it can be cracked, discovered by a misplaced Post-It note, or compromised by some other unknown s…
Re: Password expiration is dead, long live passwords
#6I'm not entirely sure that I'd agree with this mentality. Sure, at a glance it sounds good. If the password has been safeguarded, there's really not much reason to force expiration. However, wouldn't the age of the password reduce the security of it by default? The longer a password exists for, the more likely it is that it can be cracked, discovered by a misplaced Post-It note, or compromised by some other unknown s…
I'd prefer 2FA and (allowing / encouraging) longer / stronger passwords over change policies.
Re: Password expiration is dead, long live passwords
#7I've always wondered how many engineer hours have been lost on the phone with helpdesks sorting out expired passwords.
Re: Password expiration is dead, long live passwords
#8Also NIST dropped password complexity requirements. The only hard requirement is it must be 8 characters or more. New guidelines is to let users choose their own level of complexity and encourage them to make longer passwords that they can actually remember.
We would like to follow NIST 800-53, but too many customers (like Microsoft) still do not allow for the 2016 NIST changes.
Re: Password expiration is dead, long live passwords
#9I'm not entirely sure that I'd agree with this mentality. Sure, at a glance it sounds good. If the password has been safeguarded, there's really not much reason to force expiration. However, wouldn't the age of the password reduce the security of it by default? The longer a password exists for, the more likely it is that it can be cracked, discovered by a misplaced Post-It note, or compromised by some other unknown s…
Re: Password expiration is dead, long live passwords
#10I'm not entirely sure that I'd agree with this mentality. Sure, at a glance it sounds good. If the password has been safeguarded, there's really not much reason to force expiration. However, wouldn't the age of the password reduce the security of it by default? The longer a password exists for, the more likely it is that it can be cracked, discovered by a misplaced Post-It note, or compromised by some other unknown s…
Reality is that a password expiration policy quite often leads to password simplification (e.g., having an incremented number in the password, post its on the screen, ...). I'd prefer 2FA and (allowing / encouraging) longer / stronger passwords over change policies.