Live data from Hacker News

There’s no need to change passwords if they're robust, unique and not breached

tidbits.com

131–140 of 288 posts

Re: There’s no need to change passwords if they're robust, unique and not breached

#131

I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…

Working at a acquisition of a big consulting corporation. Had these recommendations in place before being acquired. We're onboarded onto better security systems by new mothership.

Password rotation every 75 days. No dictionary check. No check against known breached passwords. No real reasonable rules against insecure passwords (like ac_Paul2022 is valid 'secure' password).

Additional massive "spyware" on corporate devices in the name of security.

I don't care about security since being 'on system'. I don't do anything private on these devices. So I couldn't care less about what mothership does with their spy-/securityware on said machine.

I couldn't care less about the security. I cared when I could do something about security. When I had control about the security on the device.

But why should I nowadays care.

Re: There’s no need to change passwords if they're robust, unique and not breached

#132
> some organizations want to convince us that with the passage of time your password becomes increasingly susceptible to attack

I feel like this is somewhat true for self-fulfilling prophecy reasons; these same organizations don’t always disclose every compromise or leak of their systems, and don’t always force a password reset when it happens because it would reveal they’ve been hacked. I’m certain I have multiple online accounts at organizations that have suffered minor, major, and ransomware level breaches.

Re: There’s no need to change passwords if they're robust, unique and not breached

#133

I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…

Believe CJIS still requires annual password rotation.

Re: There’s no need to change passwords if they're robust, unique and not breached

#135
post #24

Perhaps surprisingly, US government guidelines exist, are pretty fantastic, and agree with the author: Memorized secrets SHALL be at least 8 characters in length if chosen by the subscriber. Memorized secrets chosen randomly by the CSP or verifier SHALL be at least 6 characters in length and MAY be entirely numeric. If the CSP or verifier disallows a chosen memorized secret based on its appearance on a blacklist of c…

6 characters and entirely numeric seems like a bad idea, or am I missing something?

It's...not great, but can be handy if you pick something that isn't really identifiable - mostly dates.

On a few sites I've actually used old student ID #'s - easy to type and reasonably long, with the exception of one, all are 6+ characters.

Re: There’s no need to change passwords if they're robust, unique and not breached

#137

I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…

Special characters are OK.. The casual layperson knows how to make a special character a separator.

Re: There’s no need to change passwords if they're robust, unique and not breached

#139
I think organisations forcing people to change passwords causes greater security risks. For example - if you have a bunch password character and length requirement, you will find people writing their passwords on paper or being more flexible in storing them. Because of this frequency, people will forget their password often and require assistance of IT admins or other people often through phones and emails.

I would say, strong password is slowly becoming a myth due to organizations failing understand what it is before creating a policy surrounding it.

Re: There’s no need to change passwords if they're robust, unique and not breached

#140

Earlier quoted context omitted.

A business card stored in a wallet or purse is pretty good too. After all, we're already pretty used to protecting our credit cards, identity cards, and cash.

It's pretty bad to put both a debit card and it's password together. The only reason it's even tolerable risk to walk around out in the wide random world with a debit or credit card on your person all day every day, is because somewhere else you have the means to disable it and declare it lost. This is like storing the keys to your car conveniently right on your car.

If anything it should be the "red herring" password that locks the account if retried too many times.
Post reply on HN