(Yes I evangelize password managers around here. So far I've converted 2-3 people. They are the important people with shit people might want to steal on their computers/accounts, so I'm happy with this.)
(Yes I evangelize password managers around here. So far I've converted 2-3 people. They are the important people with shit people might want to steal on their computers/accounts, so I'm happy with this.)
Every place I've ever seen or heard about with a "change every X months" system, everyone just uses a (often shared!) formula to come up with variations that satisfy the is-this-too-close-to-your-last-X-passwords checker, based on the date or whatever.
Dicks.
Disk encryption (ie, BitLocker) is supposed to prevent that from working.
There are at least two other important attack vectors against "sticky notes": accidental sharing through photographs and/or online meeting cameras, and visitors memorizing visible passwords. Both are defeated by hiding the sticky note below the keyboard, but my guess is that most people leave it visible on the monitor bezel.
IT shouldn't be able to tell anything about plaintext password similarity beyond equals or not-equals.
Of course, our company-wide email was down for 2-3 months a couple years ago due to a ransomware infection, so our IT isn't stellar. So who knows!
But at the time of the password change, no, assuming password changing requires you to enter your current password as well.
If the code that compares your current password to the new password can read the plaintext of your passwords, so too could a malicious program.
Using HTML input type="password" alone is not sufficient protection. The same steps that protect password changes from malicious attackers must necessarily protect them enforcement of bad IT security policy.
At the time of a password change, the server still has your old password hash stored, and in the process of changing it, you are sending both your old password and new password. The server can verify both that your new password and old password differ enough while also verifying that the old password you sent it is valid.
(Which - in my limited understanding of infosec - would be only marginally better than plaintext, but I can be wrong.)
It also means it should be possible to bypass that by changing the password twice or by "forgetting" your old password.
Another possibility is that they simply lie to you and the rule that is actually checked is much more permissive. I've often seen requirements that are not actually checked
I finally got all of our admin/root passwords into a password manager with sharing among job functions and our CTO as backup to ensure some level of continuity. After losing passwords to multiple production systems after someone leaving the company it was still a battle.
I'm only half-joking sadly, people just don't understand why password exist in the first place, so they comply maliciously.
I suppose someone somewhere has a maximum length that is hard to brute force, but I've never seen it.
That assumes true random passwords, most attackers can make some educated guesses and cut the problem space, but that isn't a true brute force.
But yeah, frequent password rotation is still bad.