Perhaps surprisingly, US government guidelines exist, are pretty fantastic, and agree with the author: Memorized secrets SHALL be at least 8 characters in length if chosen by the subscriber. Memorized secrets chosen randomly by the CSP or verifier SHALL be at least 6 characters in length and MAY be entirely numeric. If the CSP or verifier disallows a chosen memorized secret based on its appearance on a blacklist of c…
There’s no need to change passwords if they're robust, unique and not breached
11–20 of 288 posts
Re: There’s no need to change passwords if they're robust, unique and not breached
#12Key material rotation seems to be a sensible practice in general.
Re: There’s no need to change passwords if they're robust, unique and not breached
#13Earlier quoted context omitted.
This has been a standard IT policy for companies in the US for like 20 years. Probably 3/4 of the companies I've worked at over that time anyway.
I think the question is do people naturally change old passwords without such policies. The policies are the problem and the industry has recognized it so they’ve moved away from those recommendations.
Re: There’s no need to change passwords if they're robust, unique and not breached
#14Do people even actually change their passwords when there is no need to do so, just because the password is old?
https://keepassxc.org/blog/2020-08-15-keepassxc-password-hea...
Re: There’s no need to change passwords if they're robust, unique and not breached
#15Do people even actually change their passwords when there is no need to do so, just because the password is old?
I update my passwords from time to time. I don't trust the organizations will always say if there is breach, know there is a breach, or actually know how far and wide a breach went.
Re: There’s no need to change passwords if they're robust, unique and not breached
#16Re: There’s no need to change passwords if they're robust, unique and not breached
#17Earlier quoted context omitted.
3 of the last 4 places I've worked had as policy that you must change your password every 6 month.
My current work forces updates every 3 months. It seems more like a security issue requiring this reset so often. This is because they create another problem when anyone you talk to will say they have their password and just increment a number for every password change. That way they’re not having to remember a whole new password every few months. So there’s never much of a change in anyones password during these rot…
However, if you use a password manager, and have access to it, I think forcing key rotation on a short schedule actually increases security. The downside of course being that most people don't use a password manager, and most people use the same relatively unsecure password for everything.
Re: There’s no need to change passwords if they're robust, unique and not breached
#18I am unconvinced. What about persistent password bruteforcing? Rate limits? OK, bruteforcing is happening within those rate limits. That's how the password rots - it becomes less of a secret as many values are tried. Key material rotation seems to be a sensible practice in general.
Re: There’s no need to change passwords if they're robust, unique and not breached
#19Perhaps surprisingly, US government guidelines exist, are pretty fantastic, and agree with the author: Memorized secrets SHALL be at least 8 characters in length if chosen by the subscriber. Memorized secrets chosen randomly by the CSP or verifier SHALL be at least 6 characters in length and MAY be entirely numeric. If the CSP or verifier disallows a chosen memorized secret based on its appearance on a blacklist of c…
6 characters in length seems a bit shoddy.
Re: There’s no need to change passwords if they're robust, unique and not breached
#20When you ask people to remember too many passwords, they start writing them down and/or forgetting them, which leads to other problems.
My oldest online account - btw it is a brokerage account at one of the big brokerage houses, where a great deal of my cash and investments sit - has not asked me to change the password in close to 25 years, which I find quite funny.