Live data from Hacker News

Password expiration is dead, long live passwords

techcrunch.com

41–50 of 316 posts

Re: Password expiration is dead, long live passwords

#41
post #3

I'm not entirely sure that I'd agree with this mentality. Sure, at a glance it sounds good. If the password has been safeguarded, there's really not much reason to force expiration. However, wouldn't the age of the password reduce the security of it by default? The longer a password exists for, the more likely it is that it can be cracked, discovered by a misplaced Post-It note, or compromised by some other unknown s…

I'd suggest that users who care , when no longer forced to periodically rotate passwords, will likely choose better passwords (I know I have, where I'm no longer required to do so).

Users who don't care will still choose bad passwords, this is why 2FA is important :)

Forced periodic password rotation was mainly security theatre. Most users just choose sequence passwords, so an attacker who gets one can easily work out the others.

If you then take counter-measures to stop obvious sequences, you're heading into seriously user-unfriendly password policies, which is the kind of thing that gives security a bad name.

Far better to make use of 2FA at that point.

Re: Password expiration is dead, long live passwords

#42
post #31
post #16

We’re required to have password expiration by law in the public sector of Denmark. So I’m sure we’ll continue to have it for at least some years to come. I must admit I never really understood the function of it. Obviously lifetime access is more damaging than 3 months access, but the truly devastating thing is the unauthorised access itself not the length of it. Also the policy results in really bad practices like p…

Writing passwords on paper is recommended by security professionals, in the common case where your physical security is far more trustworthy than your digit security, because it supports the use of long, strong password. A 2FA device is very similar to a Post-It note.

Actually most security professionals have a serious downer on writing passwords down.

I can see some circumstances where it could make sense, as you say where physical security concerns are less of an issue.

That said I wouldn't say a 2FA device is like a post-it note really.

Assuming you're thinking about TOTP like google authenticator, access to the codes is protected by the devices' security, which adds a bit more to it than a post-it under a keyboard.

Re: Password expiration is dead, long live passwords

#43
post #36
post #4

The other part of this story I did not see mentioned is that I suspect that password expiration also makes organizations more vulnerable to social engineering hacks because legitimate users (I have done this) become locked out due to poorly managed password expiration, then have to call in to restore access. The use of insecure identity and authentication mechanisms like student IDs and security questions is a recipe…

Unfortunately we still have to have similar authentication methods for other password resets. Users have an alarming tendency to forget their passwords after a week or two of holiday.

Some never memorize their passwords at all. Instead relying on 'forgot' emails and "Remember Me" features entirely.

Re: Password expiration is dead, long live passwords

#44
post #24

That's exciting news, though it will take a couple of years until it trickles down to financial institutions. My bank forces me to change passwords every 3 months, and of course they also disable pasting for added security. We also have a local utility that sends you a 5 letter password upon account creation through email, and that's your password. If you try to change it, they'll send you another 5 letter one.

Bank programmers live at least 5 years in the past.

I'd say this is because it takes that long to get a feature from design to production, in a bank.

Re: Password expiration is dead, long live passwords

#45
post #36

Earlier quoted context omitted.

Unfortunately we still have to have similar authentication methods for other password resets. Users have an alarming tendency to forget their passwords after a week or two of holiday.

Some never memorize their passwords at all. Instead relying on 'forgot' emails and "Remember Me" features entirely.

Which isn't even that bad of an idea. Some website basically use this as the only way to log in.

Re: Password expiration is dead, long live passwords

#46

Earlier quoted context omitted.

Reality is that a password expiration policy quite often leads to password simplification (e.g., having an incremented number in the password, post its on the screen, ...). I'd prefer 2FA and (allowing / encouraging) longer / stronger passwords over change policies.

I prefer these methods as well, but password simplification is a user choice, not a causal effect. Any secure password generator and vault, keyfobs and various other methods are great ways to compensate for a password that expires every so often. While I'm not entirely in line with the idea of "forced" password expiration, it's often the only way to ensure that the end user actually updates their password regularly.…

> password simplification is a user choice, not a causal effect

The two are not mutually exclusive. If you require users to change passwords regularly, and also make sure the new password is sufficiently different from the last one (like, most characters must be different or something), guess what the users are likely to choose of their own so called free will.

And I'm not even speaking of how you must store a password to be able to tell that a new password is sufficiently different from all the old ones. (Hint: probably plaintext.)

> […] "forced" password expiration [is] often the only way to ensure that the end user actually updates their password regularly.

That does not work. I have defeated it in my last gig with this simple method:

  Complicatedpassword1
  Complicatedpassword2
  Complicatedpassword3
  Complicatedpassword4
  Complicatedpassword5
And I will do it again, because a complex password that never changes is much more secure than random crap that I will have to simplify just so I can remember it. Also good luck trying to defeat my strategy (or similar strategies) without storing more than a hash of the password, properly generated with a memory hard function like Argon2.

Re: Password expiration is dead, long live passwords

#47
post #32

Earlier quoted context omitted.

I came here to say this. I can't think of another way to guarantee that they aren't using the same password that they use on every website they've visited since 1997. If anyone has suggestions on this I'd love to hear it.

Not sure about the legality of this, but trying to log in to a a couple of services would be an easy test.

A secure service wouldn't have an easy way of getting at a user's password. They'd store the salted hash of a user's password, and not the password itself.

Re: Password expiration is dead, long live passwords

#48
post #34

Earlier quoted context omitted.

I prefer these methods as well, but password simplification is a user choice, not a causal effect. Any secure password generator and vault, keyfobs and various other methods are great ways to compensate for a password that expires every so often. While I'm not entirely in line with the idea of "forced" password expiration, it's often the only way to ensure that the end user actually updates their password regularly.…

> it's often the only way to ensure that the end user actually updates their password regularly It is fair to point out that the relevance of this is dependent on your attack model. If you suspect someone is trying to crack your password then just a longer password is fine. If you suspect a leak then you actually need to change/update password.

This is largely true, but we also exist in a day and age where computing clusters can fire off billions of guesses per second. Anything less than 16 digits takes a questionably small amount of time in comparison, when paired with some of the more advanced attack vectors.

Re: Password expiration is dead, long live passwords

#49
post #35
post #24

That's exciting news, though it will take a couple of years until it trickles down to financial institutions. My bank forces me to change passwords every 3 months, and of course they also disable pasting for added security. We also have a local utility that sends you a 5 letter password upon account creation through email, and that's your password. If you try to change it, they'll send you another 5 letter one.

I have 2 and 3 year CDs in a bunch of banks. (This is a common use case, people open separate accounts because of the FDIC insurance limit in any one bank). I only need to log in again 2 or 3 years after opening the account to either take the money out, or open another CD. Some of these banks expire passwords every 6 months! That's insane. I have calendar reminders set to remind me to log in and generate another pass…

I can't recommend e-banking enough. Through Fidelity you can purchase CDs from a number of banks across the country, shopping for the best interest rates. And you can create an auto-rolling CD ladder if that's your thing. I presume other e-banks like Schwab have similar features. Then you can manage all these things in one place, while getting the benefit of having your funds FDIC insured because they're technically CDs at multiple banks behind the scenes.

Re: Password expiration is dead, long live passwords

#50
post #25

Earlier quoted context omitted.

I came here to say this. I can't think of another way to guarantee that they aren't using the same password that they use on every website they've visited since 1997. If anyone has suggestions on this I'd love to hear it.

This is definitely a dilemma. If you're using Google Accounts then they have a feature for this[1]. It detects when they enter their Google password into any other site then reports it and makes them change their password. I'd love a similar feature that somehow worked with Active Directory. [1] Password Alert: https://support.google.com/a/answer/6197480

Yup, this type of feature is the answer.

It's not foolproof-perfect, but from personal experience it tends to work quickly and effectively. It requires "surveillance" of your browser/computer, but you should assume that with a work device anyways, and it can work with hashes and password fields so it's not storing your actual password or logging everything else you're doing.

Post reply on HN