I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…
Please do not group password rotation and special character restriction. One strengthens, the other weakens security. The only reason I can think that rotation would be a bad idea (aside from frustration, which is another very critical issue) is if users are not using strong passwords on each iteration. The solution is for a standard to emerge that incorporates rotation and (optionally random) password generation use…
There’s no need to change passwords if they're robust, unique and not breached
171–180 of 288 posts
Re: There’s no need to change passwords if they're robust, unique and not breached
#172I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…
Working at a acquisition of a big consulting corporation. Had these recommendations in place before being acquired. We're onboarded onto better security systems by new mothership. Password rotation every 75 days. No dictionary check. No check against known breached passwords. No real reasonable rules against insecure passwords (like ac_Paul2022 is valid 'secure' password). Additional massive "spyware" on corporate de…
Password($MONTH)($YEAR)!
Or, PasswordJanuary2022!
It easily increments to deal with stupid arbitrary rotations, passes most tests, has the small/large/number/symbol requirements.
And it's sooooooo hackable its not funny. Hell, 2 jobs ago, I ran this precisely because of 60d rotation garbage.
Re: There’s no need to change passwords if they're robust, unique and not breached
#173Earlier quoted context omitted.
Working at a acquisition of a big consulting corporation. Had these recommendations in place before being acquired. We're onboarded onto better security systems by new mothership. Password rotation every 75 days. No dictionary check. No check against known breached passwords. No real reasonable rules against insecure passwords (like ac_Paul2022 is valid 'secure' password). Additional massive "spyware" on corporate de…
I think my cynical take is to not actually care. Very few people in the whole security industry actually bother to care because it's mostly box checking regulatory requirements and/or certifications because security beyond the absolute minimum just isn't important to the job. Most places aren't being attacked or broken into, and in the slim chance it happens there's less money to say "sorry for being breached, we're…
To get there though, we need better email hiding (Apple’s Hide My Email is great for this, you can get unlimited randomly-generated @icloud.com addresss that forward to your real one) and for sites to not actually need your real name or personal information.
If done right, if randosite.com gets all emails and (even if plain-text) passwords leaked, it wouldn’t matter because only Apple can tie the email to my account, and the password would only be good on that site anyway.
If a website actually needs my real address and name for billing information, that’s another matter maybe, but even then who really cares? The existence of my home address and name doesn’t much matter if they can’t tie it to any other online identities. My address is in the phone book too… it doesn’t really give anybody new information.
Re: There’s no need to change passwords if they're robust, unique and not breached
#174I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…
Every company I work at requires regular rotation and other idiotic rules which lead people to choose demonstrably weaker passwords. My company refuses to listen to reason and accuses us of trying to subvert security when we point out their antiquated process. What do you recommend?
Re: There’s no need to change passwords if they're robust, unique and not breached
#175Earlier quoted context omitted.
Working at a acquisition of a big consulting corporation. Had these recommendations in place before being acquired. We're onboarded onto better security systems by new mothership. Password rotation every 75 days. No dictionary check. No check against known breached passwords. No real reasonable rules against insecure passwords (like ac_Paul2022 is valid 'secure' password). Additional massive "spyware" on corporate de…
I think my cynical take is to not actually care. Very few people in the whole security industry actually bother to care because it's mostly box checking regulatory requirements and/or certifications because security beyond the absolute minimum just isn't important to the job. Most places aren't being attacked or broken into, and in the slim chance it happens there's less money to say "sorry for being breached, we're…
Since seeing this I became even more of a cynic. If they want to scare us - at least they should do it intelligently.
Re: There’s no need to change passwords if they're robust, unique and not breached
#176Earlier quoted context omitted.
Check out the reference here: https://xkcd.com/936/
That's what makes it a bad password.
I don't think anyone, even the original responder, views it as an actual password we should all use.
Re: There’s no need to change passwords if they're robust, unique and not breached
#177Earlier quoted context omitted.
Please do not group password rotation and special character restriction. One strengthens, the other weakens security. The only reason I can think that rotation would be a bad idea (aside from frustration, which is another very critical issue) is if users are not using strong passwords on each iteration. The solution is for a standard to emerge that incorporates rotation and (optionally random) password generation use…
10+ years of data has strongly indicated that yes indeed "rotation is a bad idea, because users don't use strong passwords when they are forced to rotate them"
Re: There’s no need to change passwords if they're robust, unique and not breached
#178Earlier quoted context omitted.
Please do not group password rotation and special character restriction. One strengthens, the other weakens security. The only reason I can think that rotation would be a bad idea (aside from frustration, which is another very critical issue) is if users are not using strong passwords on each iteration. The solution is for a standard to emerge that incorporates rotation and (optionally random) password generation use…
Password rotation does not strengthen security.
Re: There’s no need to change passwords if they're robust, unique and not breached
#179Earlier quoted context omitted.
I know it's hard to imagine, but before we all held supercomputers in our pockets we all used to have dozens of ten-digit numbers memorized. I still remember my grade school friends' phone numbers.
You were an extreme outlier if you bothered to memorize dozens of ten digit phone numbers in the era before everyone had a cellphone. The average person doesn't even have ten good friends, much less a need to memorize dozens of phone numbers. They would buy address books / contact books to write down dozens of numbers, not memorize numbers they very rarely use.
Re: There’s no need to change passwords if they're robust, unique and not breached
#180Earlier quoted context omitted.
Password rotation does not strengthen security.
Explain?
Most people don't use password managers, and some companies block their usage. Now add a requirement of a "secure" password.