If you generate strong passwords, store them securely in a password manager and use different passwords for each account, you shouldn't need to force a password change unless the password is compromised or technology evolves to make it insecure.
If you generate strong passwords, store them securely in a password manager and use different passwords for each account, you shouldn't need to force a password change unless the password is compromised or technology evolves to make it insecure.
Really the only thing I recommend anymore is a good password managers. Use one very strong password, perhaps changed every 2-3 years if you feel the need, to unlock one or more secure private keys with which all your passwords have been encrypted.
The great thing about good password managers that use asymmetric cryptography is that my password is not really the weakest link. If you have access to my hardware, then guessing my password will potentially help you, but otherwise you'll have to break my pgp key (assuming you can also get access to the encrypted password store).
At that point I don't really care what your rotation policy is. I can generate a new password every 90 days with no real fatigue.
History shows us that sites are popped on a regular basis and their users do not always find out right away. Sometimes the org in question doesn't even know for a while.
That doesn't make sense. If a password already takes longer than the age of the universe to practically brute-force, you're not meaningfully gaining anything by forcing users to change their passwords periodically. On the other hand, you are introducing more opportunities for mistakes to occur in what is already the most dangerous failure point (the human).
I left in a reasonable acknowledgement that technology changes can make currently safe passwords weak in the future. That's a good reason to change a password. But periodic password changes don't make sense unless "periodic" refers to timescales longer than anyone here has been alive, because it's inconsequential compared to the cover time provided by a strong password.
The argument that passwords should be rotated is mostly a response to users predominantly choosing weak passwords. But if you're in a position to enforce password rotation, you're also in a position to enforce strong passwords. Password rotation is a usability-reducing, incomplete and poor method of enforcing user safety. It is wholly superseded by encouraging people to use password managers, which is a much more optimal and complete solution that does not fatigue the user. Password managers make rotation obsolete, can incorporate password breach monitoring and be made virtually frictionless (they can be incorporated directly in the browser and turned on by default).
Give hashcat a go. Give me the hashes from HN. I bet we can break most of them in a day.
good luck
You are about the 2% of the tech crowd (i.e, bay area software/data people). The vast majority of engineers do not use a password manager, let alone the entire US populace.
You severely overestimate the amount the average person cares about password security.
The point remains - if you want to follow password best practices and optimize for user safety, don't enforce arbitrary password changes. You're right about ordinary users - we should provide them with fewer opportunities to shoot themselves in the foot. The lower the frequency they have to focus on generating passwords, the better.
with my bank i have a password, an app on my phone that generates a key and if i perform significant transactions, they call me to confirm before processing it.
the idea that i'm going to use a different password for every stupid site out there that i have an account with is a bit silly. if someone desperately wants to compromise some of them then so be it. hijack my twitter if it makes you feel better. im not going to waste mental energy on securing social media.
"just use a password manager" sounds cute. password managers are compromised, too. password managers are about as trustworthy as the people who operate them. theres no way im handing my passwords for bank accounts over to some random company and for passwords that protect pointless internet nonsense, im not going to use one either because its irrelevant.
you can invoke this whole "password managers are secure" hoohaa. if they ACTUALLY encrypt your passwords properly and ACTUALLY dont save them on their own servers for whatever they want to do with them later, then yes, they probably are secure. but theres no way to be sure that thats the case. Trusting a password manager introduces more uncertainty into your password woes than they will ever make you more secure, if you really think this whole thing through.
the other issue with a password manager is that in theory, they work across platforms. that ends rather abruptly when youre not in a browser and need to enter a password into an app on your phone.
This is not the case for PasswordSafe, not the case for the various Keepass implementations out there, and not the case for several other, lesser known projects.
I am a happy, contended and reasonably safe KeepassX user since many years ago. While I do see the point of two factor auth in certain situations, I sincerely hop and pray it never takes off in a mandatory big way, uncalled for annoyance as it is in most cases. My 36 character passwords usually do the job just fine.
This is a bit short sited; if you use the same password for everything and your Twitter account gets broken into, then every site where you have the same email address is potentially also broken into
I use the standalone KeePass app across all my devices, and can paste passwords into apps with no browser access required. I believe KeePass is widely regarded by those who know more than me as cryptographically solid. The only pain point is keeping the databases synchronized across all devices, but it's not that difficult.