Live data from Hacker News

Frequent Password Changes Is a Bad Security Idea

schneier.com

11–20 of 59 posts

Re: Frequent Password Changes Is a Bad Security Idea

#12
post #9

It's a double sword. The true issue with frequent password change is people really don't want to be creative. They ended up either changing one letter, or adding an extra letter. At least do a quick distance check and deny password at 90% similarity.

Oh, yeah. They'll never just write it down if you do that.

Re: Frequent Password Changes Is a Bad Security Idea

#13
post #7

I usually just make up a crazy long sentence I'll remember, with no logical order in it. Something funny to me so I'll easily remember it. Throw in some assortment of numbers and symbols. Bam! Works like a charm!

Then the sysadmin hits you with a "at least 8 characters, no more than 13, one uppercase, one lowercase, a number, a special character, but not one that can't be encoded in EBCDIC and the password must differ in at least three places from the last 10 you used."

Re: Frequent Password Changes Is a Bad Security Idea

#15
post #6

For those who work at corporations with password rotation policies, it may actually be a good way to get creative. This guy changed password rotations into a lifehack: https://medium.com/the-lighthouse/how-a-password-changed-my-... Previous discussion on it: https://news.ycombinator.com/item?id=8015470

Thanks for the link, I reread it. Nice story but I think I can guess his current password now: "Plus, if you’re interested in more of this, I’m writing a book!" :)

Re: Frequent Password Changes Is a Bad Security Idea

#16
post #14

At a client's who requires frequent password changes, people simply write out their passwords on post it notes that they stick onto their screens. Some security. (That's a bank, by the way).

OTOH, maybe coworkers are more trustworthy than external hackers running cracking tools? Might be true at some companies... (I still hate being forced to change passwords.)

Re: Frequent Password Changes Is a Bad Security Idea

#19
post #14

At a client's who requires frequent password changes, people simply write out their passwords on post it notes that they stick onto their screens. Some security. (That's a bank, by the way).

Schneier actually recommends writing down passwords

https://www.schneier.com/blog/archives/2005/06/write_down_yo...

Re: Frequent Password Changes Is a Bad Security Idea

#20
Does anyone actually have data showing that frequent password changes lead to better security?

Because to me requiring frequent password change seems like the ultimate non-technical management blunder: management wants to say they did something to prevent hacks, so they ask IT to require password changes; IT doesn't want to be blamed so they implement it; users comply with the requirements but can't remember their new password (and don't really care about the company's security in the first place), so they come up with something insecure and keep it somewhere even less secure.

Post reply on HN