Forcing people to change their passwords is officially a bad idea
newscientist.com
newscientist.com
[PDF] https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...
> Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator. (page 14)
What's new in 2024's draft is changing this from "SHOULD NOT" to "SHALL NOT"
do you see how what I end up having to do absolutely circumvents the security of rotating a password.
If you want them to change the playbook, it'll involve some schlub having to run from pillar to post between those organizations, trying to get everyone to agree to a change to this policy, and you can bet he or she is not paid or motivated to do this. If another vendor comes along who will go with the flow, they get the sale.
MFA is a step in this direction, and done right, it should be able to alert admins and users alike that compromise and stuffing is in- progress.
Password managers and generators can make unique passwords easy as pie, thereby reducing the rampant reuse, and unwillingness to reset passwords when necessary.
Magic links and passkeys can make passwords obsolete. CAPTCHAs interfere with automated stuffing operations.
The largest services are also developing sophisticated measures of device fingerprinting and trust, of which attestation is the endgame. Y'all don't enjoy credential stuffing or data breaches, but love rooting and rail against attestation, so do you want to have your cake and eat it too?