Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. Password policy

Password policy

Scheduled Pinned Locked Moved The Lounge
securityquestionannouncement
51 Posts 29 Posters 2 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A Offline
    A Offline
    A_Griffin
    wrote on last edited by
    #1

    One of my clients, with whom I have an email account set up, has a company policy on enforced password changes every month, which drives me nuts. I've tried to connive them that the received wisdom these days from security experts is that this is not a good idea - eg: The problems with forcing regular password expiry - NCSC Site[^] Time to rethink mandatory password changes | Federal Trade Commission[^] but as I'm not really a security expert myself perhaps I shouldn't be pushing this... anyway, they aren't listening to me.... but it's a pain in the derrierre .... am I right, or are they?

    L Kornfeld Eliyahu PeterK C realJSOPR P 22 Replies Last reply
    0
    • A A_Griffin

      One of my clients, with whom I have an email account set up, has a company policy on enforced password changes every month, which drives me nuts. I've tried to connive them that the received wisdom these days from security experts is that this is not a good idea - eg: The problems with forcing regular password expiry - NCSC Site[^] Time to rethink mandatory password changes | Federal Trade Commission[^] but as I'm not really a security expert myself perhaps I shouldn't be pushing this... anyway, they aren't listening to me.... but it's a pain in the derrierre .... am I right, or are they?

      L Offline
      L Offline
      Lost User
      wrote on last edited by
      #2

      You are right, such a policy serves no real purpose. If someone's account gets hacked then their data is compromised at that point. So changing the password in a week will not do much good.

      1 Reply Last reply
      0
      • A A_Griffin

        One of my clients, with whom I have an email account set up, has a company policy on enforced password changes every month, which drives me nuts. I've tried to connive them that the received wisdom these days from security experts is that this is not a good idea - eg: The problems with forcing regular password expiry - NCSC Site[^] Time to rethink mandatory password changes | Federal Trade Commission[^] but as I'm not really a security expert myself perhaps I shouldn't be pushing this... anyway, they aren't listening to me.... but it's a pain in the derrierre .... am I right, or are they?

        Kornfeld Eliyahu PeterK Offline
        Kornfeld Eliyahu PeterK Offline
        Kornfeld Eliyahu Peter
        wrote on last edited by
        #3

        We have an ISO, which forces us to change password every 3 months and keep history of eight 'ages', and of course it must be a complex password... The only result is that now all manage a text/excel file to keep tracking of the 8 'ages' and complexity... also all creates password based on a pattern... I feel so safe... :-) The first thing I done after the first period is remove this from my user...

        Skipper: We'll fix it. Alex: Fix it? How you gonna fix this? Skipper: Grit, spit and a whole lotta duct tape.

        "It never ceases to amaze me that a spacecraft launched in 1977 can be fixed remotely from Earth." ― Brian Cox

        J H 2 Replies Last reply
        0
        • Kornfeld Eliyahu PeterK Kornfeld Eliyahu Peter

          We have an ISO, which forces us to change password every 3 months and keep history of eight 'ages', and of course it must be a complex password... The only result is that now all manage a text/excel file to keep tracking of the 8 'ages' and complexity... also all creates password based on a pattern... I feel so safe... :-) The first thing I done after the first period is remove this from my user...

          Skipper: We'll fix it. Alex: Fix it? How you gonna fix this? Skipper: Grit, spit and a whole lotta duct tape.

          J Offline
          J Offline
          Jorgen Andersson
          wrote on last edited by
          #4

          So change your password every month to My_ridiculous_password_1 through My_ridiculous_password_12 and then start over from the beginning.

          Wrong is evil and must be defeated. - Jeff Ello

          A R 2 Replies Last reply
          0
          • A A_Griffin

            One of my clients, with whom I have an email account set up, has a company policy on enforced password changes every month, which drives me nuts. I've tried to connive them that the received wisdom these days from security experts is that this is not a good idea - eg: The problems with forcing regular password expiry - NCSC Site[^] Time to rethink mandatory password changes | Federal Trade Commission[^] but as I'm not really a security expert myself perhaps I shouldn't be pushing this... anyway, they aren't listening to me.... but it's a pain in the derrierre .... am I right, or are they?

            C Offline
            C Offline
            CPallini
            wrote on last edited by
            #5

            Waste of developer time.

            1 Reply Last reply
            0
            • A A_Griffin

              One of my clients, with whom I have an email account set up, has a company policy on enforced password changes every month, which drives me nuts. I've tried to connive them that the received wisdom these days from security experts is that this is not a good idea - eg: The problems with forcing regular password expiry - NCSC Site[^] Time to rethink mandatory password changes | Federal Trade Commission[^] but as I'm not really a security expert myself perhaps I shouldn't be pushing this... anyway, they aren't listening to me.... but it's a pain in the derrierre .... am I right, or are they?

              realJSOPR Offline
              realJSOPR Offline
              realJSOP
              wrote on last edited by
              #6

              It's their server, so they're right, so you have to deal with it. It is, however, your right to complain bitterly to whomever will listen.

              ".45 ACP - because shooting twice is just silly" - JSOP, 2010
              -----
              You can never have too much ammo - unless you're swimming, or on fire. - JSOP, 2010
              -----
              When you pry the gun from my cold dead hands, be careful - the barrel will be very hot. - JSOP, 2013

              R 1 Reply Last reply
              0
              • A A_Griffin

                One of my clients, with whom I have an email account set up, has a company policy on enforced password changes every month, which drives me nuts. I've tried to connive them that the received wisdom these days from security experts is that this is not a good idea - eg: The problems with forcing regular password expiry - NCSC Site[^] Time to rethink mandatory password changes | Federal Trade Commission[^] but as I'm not really a security expert myself perhaps I shouldn't be pushing this... anyway, they aren't listening to me.... but it's a pain in the derrierre .... am I right, or are they?

                P Offline
                P Offline
                PIEBALDconsult
                wrote on last edited by
                #7

                You're both right.

                1 Reply Last reply
                0
                • J Jorgen Andersson

                  So change your password every month to My_ridiculous_password_1 through My_ridiculous_password_12 and then start over from the beginning.

                  Wrong is evil and must be defeated. - Jeff Ello

                  A Offline
                  A Offline
                  A_Griffin
                  wrote on last edited by
                  #8

                  Head of IT at another company I work for sent me a login for one of their systems... the password? W3bl0g1n! :omg:

                  J 1 Reply Last reply
                  0
                  • A A_Griffin

                    One of my clients, with whom I have an email account set up, has a company policy on enforced password changes every month, which drives me nuts. I've tried to connive them that the received wisdom these days from security experts is that this is not a good idea - eg: The problems with forcing regular password expiry - NCSC Site[^] Time to rethink mandatory password changes | Federal Trade Commission[^] but as I'm not really a security expert myself perhaps I shouldn't be pushing this... anyway, they aren't listening to me.... but it's a pain in the derrierre .... am I right, or are they?

                    L Offline
                    L Offline
                    Lost User
                    wrote on last edited by
                    #9

                    Such passwords will be written down. If someone changes the lock on their front-door each month, I'd be inclined to say that they haven't looked into securing the house at all and are merely copying others. I'd also be testing their password recovery/reset options at least twice a month :thumbsup:

                    Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] "If you just follow the bacon Eddy, wherever it leads you, then you won't have to think about politics." -- Some Bell.

                    1 Reply Last reply
                    0
                    • A A_Griffin

                      Head of IT at another company I work for sent me a login for one of their systems... the password? W3bl0g1n! :omg:

                      J Offline
                      J Offline
                      Jorgen Andersson
                      wrote on last edited by
                      #10

                      Nice. What was the name of the company again?

                      Wrong is evil and must be defeated. - Jeff Ello

                      F 1 Reply Last reply
                      0
                      • A A_Griffin

                        One of my clients, with whom I have an email account set up, has a company policy on enforced password changes every month, which drives me nuts. I've tried to connive them that the received wisdom these days from security experts is that this is not a good idea - eg: The problems with forcing regular password expiry - NCSC Site[^] Time to rethink mandatory password changes | Federal Trade Commission[^] but as I'm not really a security expert myself perhaps I shouldn't be pushing this... anyway, they aren't listening to me.... but it's a pain in the derrierre .... am I right, or are they?

                        N Offline
                        N Offline
                        Nathan Minier
                        wrote on last edited by
                        #11

                        It depends. If they're in an industry that has applicable cyber regulation then they may absolutely need to do this to maintain compliance. Thirty days seems a little on the sharp side, but that's all contingent on the laws in the primary operational area for the company. Also, the general "wisdom" on the security side is that complex passwords that are changed on a regular basis are still a fundamental security practice. The zeitgeist has not shifted on that; though there are a number of increasingly vocal individuals that advocate for a less complex strategy, they don't represent the viewpoint of the community as a whole. Use [KeePass](https://keepass.info/) to keep it easy. I just use the "Generate from last" and go.

                        "There are three kinds of lies: lies, damned lies and statistics." - Benjamin Disraeli

                        L 1 Reply Last reply
                        0
                        • A A_Griffin

                          One of my clients, with whom I have an email account set up, has a company policy on enforced password changes every month, which drives me nuts. I've tried to connive them that the received wisdom these days from security experts is that this is not a good idea - eg: The problems with forcing regular password expiry - NCSC Site[^] Time to rethink mandatory password changes | Federal Trade Commission[^] but as I'm not really a security expert myself perhaps I shouldn't be pushing this... anyway, they aren't listening to me.... but it's a pain in the derrierre .... am I right, or are they?

                          Z Offline
                          Z Offline
                          ZurdoDev
                          wrote on last edited by
                          #12

                          A_Griffin wrote:

                          I'm not really a security expert

                          I'm not sure anyone really is. It's my understanding that most major security breaches are not through guessing someone's password but through other security holes so I don't think these policies do any good at all.

                          Everyone is born right handed. Only the strongest overcome it. Fight for left-handed rights and hand equality.

                          1 Reply Last reply
                          0
                          • N Nathan Minier

                            It depends. If they're in an industry that has applicable cyber regulation then they may absolutely need to do this to maintain compliance. Thirty days seems a little on the sharp side, but that's all contingent on the laws in the primary operational area for the company. Also, the general "wisdom" on the security side is that complex passwords that are changed on a regular basis are still a fundamental security practice. The zeitgeist has not shifted on that; though there are a number of increasingly vocal individuals that advocate for a less complex strategy, they don't represent the viewpoint of the community as a whole. Use [KeePass](https://keepass.info/) to keep it easy. I just use the "Generate from last" and go.

                            "There are three kinds of lies: lies, damned lies and statistics." - Benjamin Disraeli

                            L Offline
                            L Offline
                            Lost User
                            wrote on last edited by
                            #13

                            Yes, if they are too lazy to restrict access for ex-employees, then it would pay to change those passwords every 30 days. Would give said employee to the end of the month to create chaos. It is nonsense.

                            Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] "If you just follow the bacon Eddy, wherever it leads you, then you won't have to think about politics." -- Some Bell.

                            N 1 Reply Last reply
                            0
                            • A A_Griffin

                              One of my clients, with whom I have an email account set up, has a company policy on enforced password changes every month, which drives me nuts. I've tried to connive them that the received wisdom these days from security experts is that this is not a good idea - eg: The problems with forcing regular password expiry - NCSC Site[^] Time to rethink mandatory password changes | Federal Trade Commission[^] but as I'm not really a security expert myself perhaps I shouldn't be pushing this... anyway, they aren't listening to me.... but it's a pain in the derrierre .... am I right, or are they?

                              R Offline
                              R Offline
                              raddevus
                              wrote on last edited by
                              #14

                              Not just gratuitous self-promotion (because that doesn't work well) but you could really try my C'YaPass program (Users Hate Passwords (We're All Users): Never Memorize a Password Again[^]). It's free, open source, and there is code for 4 major platforms (windows, web, android, ios). The coolest thing in the latest version is that it remembers all those annoying password requirements* now. *Add uppercase, add special character, length req

                              A 1 Reply Last reply
                              0
                              • J Jorgen Andersson

                                Nice. What was the name of the company again?

                                Wrong is evil and must be defeated. - Jeff Ello

                                F Offline
                                F Offline
                                F ES Sitecore
                                wrote on last edited by
                                #15

                                M1cro50ft.

                                1 Reply Last reply
                                0
                                • L Lost User

                                  Yes, if they are too lazy to restrict access for ex-employees, then it would pay to change those passwords every 30 days. Would give said employee to the end of the month to create chaos. It is nonsense.

                                  Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] "If you just follow the bacon Eddy, wherever it leads you, then you won't have to think about politics." -- Some Bell.

                                  N Offline
                                  N Offline
                                  Nathan Minier
                                  wrote on last edited by
                                  #16

                                  No, if the organization is subject to regulation then out-processing requirements are likely required as well, which should include account closure. Of course, if there are a ton of different systems without a central AAA mechanism then it might be as you suggest, but only a complete moron would consider that a security strategy. This isn't an insider threat mitigation strategy. As I said, 30 days is a bit much, but at least 90 (with deviation requirements) is pretty on-point to prevent re-use issues if a third party is compromised. It's not perfect, but it's far better than nothing.

                                  "There are three kinds of lies: lies, damned lies and statistics." - Benjamin Disraeli

                                  L 1 Reply Last reply
                                  0
                                  • N Nathan Minier

                                    No, if the organization is subject to regulation then out-processing requirements are likely required as well, which should include account closure. Of course, if there are a ton of different systems without a central AAA mechanism then it might be as you suggest, but only a complete moron would consider that a security strategy. This isn't an insider threat mitigation strategy. As I said, 30 days is a bit much, but at least 90 (with deviation requirements) is pretty on-point to prevent re-use issues if a third party is compromised. It's not perfect, but it's far better than nothing.

                                    "There are three kinds of lies: lies, damned lies and statistics." - Benjamin Disraeli

                                    L Offline
                                    L Offline
                                    Lost User
                                    wrote on last edited by
                                    #17

                                    Nathan Minier wrote:

                                    This isn't an insider threat mitigation strategy. As I said, 30 days is a bit much, but at least 90 (with deviation requirements) is pretty on-point to prevent re-use issues if a third party is compromised. It's not perfect, but it's far better than nothing.

                                    It is patchwork for someone who is too lazy to control the entire chain, and it is evil; it gives the impression of added security, where there isn't.

                                    Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] "If you just follow the bacon Eddy, wherever it leads you, then you won't have to think about politics." -- Some Bell.

                                    N 1 Reply Last reply
                                    0
                                    • A A_Griffin

                                      One of my clients, with whom I have an email account set up, has a company policy on enforced password changes every month, which drives me nuts. I've tried to connive them that the received wisdom these days from security experts is that this is not a good idea - eg: The problems with forcing regular password expiry - NCSC Site[^] Time to rethink mandatory password changes | Federal Trade Commission[^] but as I'm not really a security expert myself perhaps I shouldn't be pushing this... anyway, they aren't listening to me.... but it's a pain in the derrierre .... am I right, or are they?

                                      T Offline
                                      T Offline
                                      Tim Carmichael
                                      wrote on last edited by
                                      #18

                                      A_Griffin wrote:

                                      One of my clients

                                      They are paying you to do a job; either do it with their requirements or don't get paid. Have you heard of how many control systems get hacked because people didn't change default passwords or change them on a regular basis? It is not so much an issue in the U.S.A. where companies are required by federal law to maintain secure environments, but it is still a threat.

                                      A 1 Reply Last reply
                                      0
                                      • L Lost User

                                        Nathan Minier wrote:

                                        This isn't an insider threat mitigation strategy. As I said, 30 days is a bit much, but at least 90 (with deviation requirements) is pretty on-point to prevent re-use issues if a third party is compromised. It's not perfect, but it's far better than nothing.

                                        It is patchwork for someone who is too lazy to control the entire chain, and it is evil; it gives the impression of added security, where there isn't.

                                        Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] "If you just follow the bacon Eddy, wherever it leads you, then you won't have to think about politics." -- Some Bell.

                                        N Offline
                                        N Offline
                                        Nathan Minier
                                        wrote on last edited by
                                        #19

                                        I disagree. There is no "control the entire chain" when a user can use the same password on my system as on a third party system, and I have no idea what precautions that system might have in place. Compared to the risk of compromise of credentials through third parties, the risk that an employee might keep a written ledger of passwords (or use a password manager) is much easier to accept. As an SA or ISSO, I have no control over what passwords users have on other systems; but if I make them change it often enough I can reduce the risk of password reuse, and risk reduction is all that you can do in security. Not having password change requirements is frankly "lazy", as you are not only putting your system at risk, but any other that the user might have an account with.

                                        "There are three kinds of lies: lies, damned lies and statistics." - Benjamin Disraeli

                                        L 1 Reply Last reply
                                        0
                                        • N Nathan Minier

                                          I disagree. There is no "control the entire chain" when a user can use the same password on my system as on a third party system, and I have no idea what precautions that system might have in place. Compared to the risk of compromise of credentials through third parties, the risk that an employee might keep a written ledger of passwords (or use a password manager) is much easier to accept. As an SA or ISSO, I have no control over what passwords users have on other systems; but if I make them change it often enough I can reduce the risk of password reuse, and risk reduction is all that you can do in security. Not having password change requirements is frankly "lazy", as you are not only putting your system at risk, but any other that the user might have an account with.

                                          "There are three kinds of lies: lies, damned lies and statistics." - Benjamin Disraeli

                                          L Offline
                                          L Offline
                                          Lost User
                                          wrote on last edited by
                                          #20

                                          Nathan Minier wrote:

                                          but if I make them change it often enough I can reduce the risk of password reuse

                                          No, now you are increasing that risk. Januari01, February02, March03..

                                          Nathan Minier wrote:

                                          and risk reduction is all that you can do in security

                                          My world has to be black and white; either something can be trusted, or it can't. If it is outside my control, there will be no trust.

                                          Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] "If you just follow the bacon Eddy, wherever it leads you, then you won't have to think about politics." -- Some Bell.

                                          N 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups