Live data from Hacker News

There’s no need to change passwords if they're robust, unique and not breached

tidbits.com

191–200 of 288 posts

Re: There’s no need to change passwords if they're robust, unique and not breached

#191
post #180

Earlier quoted context omitted.

Explain?

The intent of the policy doesn't match the real-world implementation of users. Users are lazy. Users will alter a single character or digit in the password and call it changed. Most people don't use password managers, and some companies block their usage. Now add a requirement of a "secure" password.

Automated password rotation would use machine generated highly secure passwords. I do not see your point.

This issue for master passwords is a bit harder, yes.

Re: There’s no need to change passwords if they're robust, unique and not breached

#192

I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…

Every company I work at requires regular rotation and other idiotic rules which lead people to choose demonstrably weaker passwords. My company refuses to listen to reason and accuses us of trying to subvert security when we point out their antiquated process. What do you recommend?

I recommend not working for a company that thinks its own employees are trying to subvert security. What level of trust is that?

Re: There’s no need to change passwords if they're robust, unique and not breached

#193

I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…

Working at a acquisition of a big consulting corporation. Had these recommendations in place before being acquired. We're onboarded onto better security systems by new mothership. Password rotation every 75 days. No dictionary check. No check against known breached passwords. No real reasonable rules against insecure passwords (like ac_Paul2022 is valid 'secure' password). Additional massive "spyware" on corporate de…

Most of these policies boil down to regulations or compliance. The financial industry, ironically, is a huge propagator of antiquated security controls.

We all knew that the controls were bad, but we had to use them

Re: There’s no need to change passwords if they're robust, unique and not breached

#194

I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…

Working at a acquisition of a big consulting corporation. Had these recommendations in place before being acquired. We're onboarded onto better security systems by new mothership. Password rotation every 75 days. No dictionary check. No check against known breached passwords. No real reasonable rules against insecure passwords (like ac_Paul2022 is valid 'secure' password). Additional massive "spyware" on corporate de…

I worked at a small consultancy. We started without password rotation requirements, because it's more secure. We had to add them, because our clients' legal teams started requiring that their contracts with vendors mandate industry-standard security practices. Your employer was probably in a similar situation: certain practices are mandated by customer contracts, not actual security assessments.

It takes a long time for industry-standard to catch up to actual practice.

Re: There’s no need to change passwords if they're robust, unique and not breached

#195

Earlier quoted context omitted.

Every company I work at requires regular rotation and other idiotic rules which lead people to choose demonstrably weaker passwords. My company refuses to listen to reason and accuses us of trying to subvert security when we point out their antiquated process. What do you recommend?

I recommend not working for a company that thinks its own employees are trying to subvert security. What level of trust is that?

The level of trust justified by pretty much all of security research; the insider risk is by far the biggest security risk for most organizations, whether you are talking about physical loss or infosec.

Re: There’s no need to change passwords if they're robust, unique and not breached

#196

I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…

Please do not group password rotation and special character restriction. One strengthens, the other weakens security. The only reason I can think that rotation would be a bad idea (aside from frustration, which is another very critical issue) is if users are not using strong passwords on each iteration. The solution is for a standard to emerge that incorporates rotation and (optionally random) password generation use…

Another reason rotation is bad is because it put undo burden on the user. You're now combining the unneeded burden of password rotation with the unneeded burden of a randomly generated password for a user to remember.

Of course, by remember, I mean put in a .txt file somewhere.

Both of your suggests disregards the user's experience and security is only ever as good as your user's willingness to use it.

Re: There’s no need to change passwords if they're robust, unique and not breached

#197
post #180

Earlier quoted context omitted.

The intent of the policy doesn't match the real-world implementation of users. Users are lazy. Users will alter a single character or digit in the password and call it changed. Most people don't use password managers, and some companies block their usage. Now add a requirement of a "secure" password.

Automated password rotation would use machine generated highly secure passwords. I do not see your point. This issue for master passwords is a bit harder, yes.

If you're using machine-generated passwords, then what's the point of rotating them?

Re: There’s no need to change passwords if they're robust, unique and not breached

#199

I am unconvinced. What about persistent password bruteforcing? Rate limits? OK, bruteforcing is happening within those rate limits. That's how the password rots - it becomes less of a secret as many values are tried. Key material rotation seems to be a sensible practice in general.

> it becomes less of a secret as many values are tried. Not meaningfully. Let's take my Hacker News password and we'll imagine you happen to know (somehow) exactly what the format is, so then you start guessing. And we'll imagine you can make 1 billion login attempts per second, which in fact I'd guess will make dang pretty unhappy 'cos the servers won't like that. And maybe you get to do this on a billion computers,…

Let's take my library account. Sequentially issued card numbers, 4-digit PINs. :(

Re: There’s no need to change passwords if they're robust, unique and not breached

#200

I feel like this post was intended to inflame or shock the reader with the writers stance on password policy. But anyone who has been in security for more than 1 month knows that regular password rotation has not been a recommendation for over 5 years. Both NIST, and MS have been trying to get the world to move to long, never rotated password, so long as those passwords are dictionary checked. Every company (all 3 of…

Both password rotation and special char requirements (which often interferes with strong password generations because other systems don't support same character sets) are very much alive and well in govt contracting / vendor requirement land. Ie, they are still very very common.

In a business when the password reset request rate gets high, it usually gets easier and easier to reset passwords. I worked with a govt system as a contractor supporting a subcontractor. They had such annoying password rotations and a DOUBLE password system (users didn't understand, but one was for a VPN sort of thing and the next was for the app) that coupled with frequent rotations of both passwords and very slow account provisioning meant reset requests were crazy high.

But the good part? You could literally call the number, provide a username, and then they'd read you the temporary password right then. They'd actually outsourced password reset because the volume was so high they couldn't support it with their staff!

A) Hi, I need a password reset. B) Sure, what's the username C) It's XXXX D) Do you need password1 or password2 reset? E) I'm not sure? F) No problem. Use AAAA for the first password and BBBB for the second.

It was basically the system routing around damage so folks could get their jobs done.

Post reply on HN