Live data from Hacker News

There’s no need to change passwords if they're robust, unique and not breached

tidbits.com

171–180 of 288 posts

Re: There’s no need to change passwords if they're robust, unique and not breached

#171

I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…

Please do not group password rotation and special character restriction. One strengthens, the other weakens security. The only reason I can think that rotation would be a bad idea (aside from frustration, which is another very critical issue) is if users are not using strong passwords on each iteration. The solution is for a standard to emerge that incorporates rotation and (optionally random) password generation use…

Password rotation does not strengthen security.

Re: There’s no need to change passwords if they're robust, unique and not breached

#172

I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…

Working at a acquisition of a big consulting corporation. Had these recommendations in place before being acquired. We're onboarded onto better security systems by new mothership. Password rotation every 75 days. No dictionary check. No check against known breached passwords. No real reasonable rules against insecure passwords (like ac_Paul2022 is valid 'secure' password). Additional massive "spyware" on corporate de…

I know of a non-zero and non-one amounts of the following passwords in idiotic "60 day rotation policies"

Password($MONTH)($YEAR)!

Or, PasswordJanuary2022!

It easily increments to deal with stupid arbitrary rotations, passes most tests, has the small/large/number/symbol requirements.

And it's sooooooo hackable its not funny. Hell, 2 jobs ago, I ran this precisely because of 60d rotation garbage.

Re: There’s no need to change passwords if they're robust, unique and not breached

#173
post #152

Earlier quoted context omitted.

Working at a acquisition of a big consulting corporation. Had these recommendations in place before being acquired. We're onboarded onto better security systems by new mothership. Password rotation every 75 days. No dictionary check. No check against known breached passwords. No real reasonable rules against insecure passwords (like ac_Paul2022 is valid 'secure' password). Additional massive "spyware" on corporate de…

I think my cynical take is to not actually care. Very few people in the whole security industry actually bother to care because it's mostly box checking regulatory requirements and/or certifications because security beyond the absolute minimum just isn't important to the job. Most places aren't being attacked or broken into, and in the slim chance it happens there's less money to say "sorry for being breached, we're…

The corollary of this is that, as a user, you need to do your best do ensure that when your account is broken into, that it doesn’t matter to you either.

To get there though, we need better email hiding (Apple’s Hide My Email is great for this, you can get unlimited randomly-generated @icloud.com addresss that forward to your real one) and for sites to not actually need your real name or personal information.

If done right, if randosite.com gets all emails and (even if plain-text) passwords leaked, it wouldn’t matter because only Apple can tie the email to my account, and the password would only be good on that site anyway.

If a website actually needs my real address and name for billing information, that’s another matter maybe, but even then who really cares? The existence of my home address and name doesn’t much matter if they can’t tie it to any other online identities. My address is in the phone book too… it doesn’t really give anybody new information.

Re: There’s no need to change passwords if they're robust, unique and not breached

#174

I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…

Every company I work at requires regular rotation and other idiotic rules which lead people to choose demonstrably weaker passwords. My company refuses to listen to reason and accuses us of trying to subvert security when we point out their antiquated process. What do you recommend?

[deleted]

Re: There’s no need to change passwords if they're robust, unique and not breached

#175
post #152

Earlier quoted context omitted.

Working at a acquisition of a big consulting corporation. Had these recommendations in place before being acquired. We're onboarded onto better security systems by new mothership. Password rotation every 75 days. No dictionary check. No check against known breached passwords. No real reasonable rules against insecure passwords (like ac_Paul2022 is valid 'secure' password). Additional massive "spyware" on corporate de…

I think my cynical take is to not actually care. Very few people in the whole security industry actually bother to care because it's mostly box checking regulatory requirements and/or certifications because security beyond the absolute minimum just isn't important to the job. Most places aren't being attacked or broken into, and in the slim chance it happens there's less money to say "sorry for being breached, we're…

Fun fact: We are being shown how dangerous this internet is. With scary looking numbers of attacks per quarter. Until one scrutinizes the slides to see that not our mothership is the target of these attacks, but that these numbers (somewhat in the range of 350 - 500) are global numbers on companies of any size.

Since seeing this I became even more of a cynic. If they want to scare us - at least they should do it intelligently.

Re: There’s no need to change passwords if they're robust, unique and not breached

#176
post #164
post #130

Earlier quoted context omitted.

Check out the reference here: https://xkcd.com/936/

That's what makes it a bad password.

It's a fantastic example of both how to create memorable high entropy passwords, and a class of passwords that many systems don't allow.

I don't think anyone, even the original responder, views it as an actual password we should all use.

Re: There’s no need to change passwords if they're robust, unique and not breached

#177
post #168

Earlier quoted context omitted.

Please do not group password rotation and special character restriction. One strengthens, the other weakens security. The only reason I can think that rotation would be a bad idea (aside from frustration, which is another very critical issue) is if users are not using strong passwords on each iteration. The solution is for a standard to emerge that incorporates rotation and (optionally random) password generation use…

10+ years of data has strongly indicated that yes indeed "rotation is a bad idea, because users don't use strong passwords when they are forced to rotate them"

Please read my full comment.

Re: There’s no need to change passwords if they're robust, unique and not breached

#178

Earlier quoted context omitted.

Please do not group password rotation and special character restriction. One strengthens, the other weakens security. The only reason I can think that rotation would be a bad idea (aside from frustration, which is another very critical issue) is if users are not using strong passwords on each iteration. The solution is for a standard to emerge that incorporates rotation and (optionally random) password generation use…

Password rotation does not strengthen security.

Explain?

Re: There’s no need to change passwords if they're robust, unique and not breached

#179

Earlier quoted context omitted.

I know it's hard to imagine, but before we all held supercomputers in our pockets we all used to have dozens of ten-digit numbers memorized. I still remember my grade school friends' phone numbers.

You were an extreme outlier if you bothered to memorize dozens of ten digit phone numbers in the era before everyone had a cellphone. The average person doesn't even have ten good friends, much less a need to memorize dozens of phone numbers. They would buy address books / contact books to write down dozens of numbers, not memorize numbers they very rarely use.

I think "dozens" is an overstatement, but 10-20 wasn't unusual. In college, I could have given you the number for a dozen delivery restaurants, easily. Not proud of it, just saying. That's not counting family, friends, services like taxi companies and movie theaters, and work.

Re: There’s no need to change passwords if they're robust, unique and not breached

#180

Earlier quoted context omitted.

Password rotation does not strengthen security.

Explain?

The intent of the policy doesn't match the real-world implementation of users. Users are lazy. Users will alter a single character or digit in the password and call it changed.

Most people don't use password managers, and some companies block their usage. Now add a requirement of a "secure" password.

Post reply on HN