Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Security IT

Please Do Not Change Your Password 497

cxbrx writes "Mark Pothier's Boston Globe article, 'Please do not change your password,' covers a paper by Microsoft Researcher Cormac Herley, 'So Long, and No Thanks for the Externalities: the Rational Rejection of Security Advice by Users,' from the 2009 New Security Paradigms Workshop. Herley argues 'that user's rejection of the security advice they receive is entirely rational from an economic perspective.' Herley discusses 'password rules,' 'teaching users to recognize phishing sites by reading URLs,' and 'certificate errors.' Users obviously choose bad passwords, but does password aging actually help? There was some discussion on TechRepublic. I'm especially interested in hearing about studies about password aging."
This discussion has been archived. No new comments can be posted.

Please Do Not Change Your Password

Comments Filter:
  • by Anonymous Coward on Tuesday April 13, 2010 @01:12PM (#31834526)

    hunter2

  • by Hatta ( 162192 ) on Tuesday April 13, 2010 @01:13PM (#31834548) Journal

    We have a password expiration policy at my work. Every time I change my password I have to memorize a new one. So I pick a password that's easy to remember, as such it's also easy to guess. If I could just memorize a password once, and keep it forever I'd be using a password that's essentially random. This policy is nonsense.

    • by oldspewey ( 1303305 ) on Tuesday April 13, 2010 @01:18PM (#31834630)
      And don't forget the arbitrary rules put in place to ensure "strong" passwords - with each ruleset being different depending on the environment or portal being secured. My personal favourite: "No repeating characters allowed." Super idea! Let's force users to weaken their passwords by eliminating the possibility of duplicate characters in strategic locations.
      • Re: (Score:2, Funny)

        by ColdWetDog ( 752185 )
        Here's a nice argument to beat the Password Police over the head with (from TFA):

        In the paper, Herley describes an admittedly crude economic analysis to determine the value of user time. He calculated that if the approximately 200 million US adults who go online earned twice the minimum wage, a minute of their time each day equals about $16 billion a year. Therefore, for any security measure to be justified, each minute users are asked to spend on it daily should reduce the harm they are exposed to by $16 b

        • by jbengt ( 874751 ) on Tuesday April 13, 2010 @03:02PM (#31836880)
          Sounds like a bad application of math to me. (I admit, though that I only skimmed through the report, so I could be wrong)
          There are two sides to a risk analysis, the probabilities and the values being risked. People will play the lottery even when they don't have a reasonable chance, because the thing being risked is not that valuable. But they are not willing to risk their life savings when the odds are slightly in their favor, because they can't repeat the bet 100 times to try and come out ahead on average.
          If I'm the owner of a business, and I'm paying my employees X time the minimum wage, and a breach costs me Y dollars, I can live with the math. But if there's even a small chance that a breach will cause the death of my business, then I'm willing to have my employees spend "more than it's worth".
      • by poptones ( 653660 ) on Tuesday April 13, 2010 @01:41PM (#31835154) Journal
        Password: Aaaaaayyy
      • by Bearhouse ( 1034238 ) on Tuesday April 13, 2010 @01:44PM (#31835212)

        And don't forget the arbitrary rules put in place to ensure "strong" passwords - with each ruleset being different depending on the environment or portal being secured. My personal favourite: "No repeating characters allowed." Super idea! Let's force users to weaken their passwords by eliminating the possibility of duplicate characters in strategic locations.

        Indeed. Similar to the Enigma: http://en.wikipedia.org/wiki/Enigma_machine [wikipedia.org]
        Where a misguided decision was taken to never let a character be encoded to itself. This actually weakened the cypher: http://en.wikipedia.org/wiki/Cryptanalysis_of_the_Enigma [wikipedia.org]

        • by UnknowingFool ( 672806 ) on Tuesday April 13, 2010 @02:55PM (#31836728)

          Actually the Enigma is a good example of how a system is weakened by its users. Yes the cipher had weaknesses such as never encoding a character to itself and that the rotors were in alphabetic order rather than randomized. But the main weakness was the users and the Allies exploited that.

          The machine itself had a number of settings. With all these settings, the Enigma messages could have daily and message specific settings. For the Army and Luftwaffe, it was left up to the operator to set them. Unfortunately, some operators were lazy and re-used settings. Also the German military had a habit of re-sending the same messages again and again for propaganda, morale, etc.

          The German Navy was much more disciplined. They issued code books that specified many of the settings per day. These settings were much more randomized. These code books were printed on specialized paper that would disintegrate in contact with water. This system was much more secure until the Allies captured some code books when they captured a German vessel. The procedure was the captain was to destroy the code books by tossing them into sea. The captain of a disabled vessel abandoned it only to return to retrieve his personal effects rather than destroy the books.

      • by MobyDisk ( 75490 ) on Tuesday April 13, 2010 @01:48PM (#31835290) Homepage

        My favorite is "password may be no longer than X characters" - why arbitrarily limit the length of them? It's especially great when X is something small like 4 (pin #s) or 8.

        • Re: (Score:3, Insightful)

          by eth1 ( 94901 )

          The thing that worries me most about that is that it seems to indicate that they're storing the passwords plain text rather than hashing them, so they're limited to whatever field width the DB designer pulled out of his ass that day.

          • Re: (Score:3, Informative)

            by greed ( 112493 )

            Even if it is a hash, the old UNIX crypt(3C) function only hashed the first 8 characters. So you could have what you thought was an arbitrarily-long password, but an attacker only needed to go after the first 8 characters.

            If you were using the presumed length to use an English phrase (for example), you could wind up with a very weak password. "passwordisreallylongsoimsafe" would be unlocked with "password", which is fairly early in the dictionary attacks I've seen.

            I normally think it's acceptable to trade

    • by r_jensen11 ( 598210 ) on Tuesday April 13, 2010 @01:21PM (#31834698)

      We have a password expiration policy at my work. Every time I change my password I have to memorize a new one. So I pick a password that's easy to remember, as such it's also easy to guess. If I could just memorize a password once, and keep it forever I'd be using a password that's essentially random. This policy is nonsense.

      Password rotation doesn't help with hackers, but it helps when a coworker learns what your password is.

    • by Jurily ( 900488 )

      Agreed. Show me one user who will memorize even two strong passwords for you. The more often you force them to change it, the more simplistic they will change it to. Is this what you want?

      If you're lucky, they'll just append something to the end of the old one, thus making the change pointless.

    • by Moryath ( 553296 )

      It depends on where you are and what level of security you need.

      Expiring passwords make sense - IF you are in a situation where you run a regular risk of passwords being exposed.

      A worse problem is the fact that people use the same password for everything - bank account, hotmail, gmail, work, etc. One of them gets compromised by someone and all of a sudden their whole life is exposed.

      Of course, the best way to get a user to be properly educated about securing their information is to have their identity stole

    • When a user changes their password, a post-it note goes on their monitor for weeks.

      If a user picks only one password and keeps it forever, they will typically pick a stronger password, protecting against brute force dictionary attacks.

      However, keeping the same password does not protect against malicious ex-employees. I know companies that do not change admin passwords, and although they are complex, previous administrators still have access to certain info if they wish.

    • Re: (Score:2, Informative)

      by Rivalz ( 1431453 )

      find a scheme
      like if it is October 2010 make your password
      11Nov2010Ber!!
      If it is December
      12Dec2010Ber!! ect
      Passwords that have rationale behind them are very easy to remember, can be very complex and sometimes easy to type.

    • by whois ( 27479 ) on Tuesday April 13, 2010 @01:31PM (#31834928) Homepage

      There is a flip-side to this. No matter how careful you think you are, you will one day expose your password in the clear. Once that happens you have no way of knowing if anyone was watching.

      Typing a password in the wrong terminal, typing a password in the wrong web field and having it autosearch google for your password. Typing your password over a bluetooth wireless keyboard with unknown encryption. Using a telnet session, etc. Logging in using a friend or co-workers PC that may have been compromised, etc.

      Because of all this, it's still a good policy to change passwords on an annual basis, with an immediate password change if you know it's been leaked.

      I encourage companies to move to single sign-on, since I consider having to memorize 17 passwords for one company to be more hassle than having to change a password frequently.

      Or having to change a password on a system you only login to once every 6 months, every time you login. I hate that. :)

      Unfortunately, it doesn't always work out because one centralized password means you trust one department of a company with access to everything (there are workarounds for this, but still company politics gets in the way)

    • by COMON$ ( 806135 ) on Tuesday April 13, 2010 @01:34PM (#31834988) Journal
      On our LAN I put rational policies in place. Essentially I look at the threat of an event and what it will take to mitigate it. If I am worried about a brute force attack I can solve that by password rotation or increasing complexity. I let the user choose which they are comfortable with. Some users dont want to use a passphrase so they have to change their password more often. Other people have realized that "I love my dog fluffy." is really easy to remember and since it meets my complexity and length requirements I make the password rotation much much longer.

      Yes, In 2008 AD you can do granular password policies, and yes this works VERY well. Not only do I have a pile of users with 15+ characters, I have users who WANT to use these passwords.

      I find that when you give the users a choice and work with them, security goes much smoother. users will always take the easiest way out, every time.

    • by mcgrew ( 92797 ) *

      From TFA:

      That poses a challenge for the security industry, Herley said. While doctors can cite statistics showing smoking causes cancer, and road-safety engineers can produce miles of numbers supporting seat belt use, computer security professionals lack such compelling evidence to give their advice clout. "Unbelievable though it might seem, we don't have data on most of the attacks we talk about," he said. "That's precisely why we're in this 'do it all' approach."

      Security professionals have no scientific

      • Re: (Score:3, Insightful)

        by John Hasler ( 414242 )

        > It goes into the password expiration paradigm as well, pointing out that if
        > someone steals your house key, they're not going to give you time to change
        > the locks; they're breaking in immediately.

        Not likely. Perhaps if they pick it out of my pocket as I am getting in the car to go to work they will walk straight up to the house and let themselves in (BTW it isn't breaking if they have a key). Far more likely, though, it will take days or weeks to figure out what the key fits, get it into the h

    • by Bert64 ( 520050 )

      Depending on how its implemented... If it's using the default options built in to active directory for instance, then the password policy only really pays lip service to security while still being extremely weak...
      You might be required to use mixed case letters and numbers, and change your password every month or so... But it still doesn't stop you having weak passwords, for instance "Password1" is perfectly valid under every implementation i've seen, and when it forces you to change your password "Password

    • How to guess someone's password, in three easy steps:

      1. Find out the name of their youngest non-estranged child. If there is a tie, pick the one with the shorter name. (e.g. Cody)
      2. Take today's date, and subtract from it the lesser of the employee's start date, or the implementation of the password expiration policy (Apr 13th 2010 - Apr 1st 2009 = 12 months)
      3. Divide the result of step 2 by the password expiration window (say 3 months)

      The password is cody4

  • by Anonymous Coward on Tuesday April 13, 2010 @01:16PM (#31834596)

    "Change your passwords and be rooted." -- JIRA attackers.

  • Ironic Juxtaposition (Score:5, Interesting)

    by Arancaytar ( 966377 ) <arancaytar.ilyaran@gmail.com> on Tuesday April 13, 2010 @01:17PM (#31834610) Homepage

    1. Apache Foundation Attacked, Passwords Stolen

    2. Please Do Not Change Your Password

    Slashdot is awesome today!

  • by Skyshadow ( 508 ) * on Tuesday April 13, 2010 @01:20PM (#31834666) Homepage

    Password aging is one of those policies that sounds like it makes some degree of sense only if you don't have any understanding of human nature.

    Here in reality, forcing people to change their password every 30 or 60 or 90 days only has a few possible results:

    (1) A lot more people writing down passwords and sticking them to their monitors. Who the hell can remember a new eight-digit string of nonsense every month?
    (2) A lot more easy-to-guess passwords
    (3) Incremented passwords (FuckTheSecurityGuys14)

    This is why I consider password policies a great indicator of where your IT department is on the "keepin' it real" scale: No restrictions, you IT people are idiots and don't care or understand security. Reasonable restrictions (min 8 characters, letters and numbers) and you're in the sweet spot. Passwords that expire every 15 minutes, your IT people are idiots and don't care or understand security.

    • by Shakrai ( 717556 )

      Passwords that expire every 15 minutes, your IT people are idiots and don't care or understand security.

      You neglected one possibility: Your IT people are sadists who are sick of dealing with lusers ;)

      • Re: (Score:3, Insightful)

        by Moryath ( 553296 )

        You neglected another possibility: your security restrictions were set by some dumbass in a state legislature who read some paper or book regarding "IT Security" and passed laws and regulations for government agencies...

      • If the lusers deserve it, is it sadistic to torture them?
    • Re: (Score:3, Informative)

      by Itninja ( 937614 )
      Yes, yes. This is all very fine. Until there is a massive security breach (like this recent one [thejournal.com]) and the CEO is looking for a place to drop the blame-hammer. Password aging may have had nothing to do with the breach, but who cares? The IS dept didn't have one? It's their fault then....
      • by ConceptJunkie ( 24823 ) on Tuesday April 13, 2010 @01:35PM (#31834990) Homepage Journal

        And this points to a huge problem in IT departments, companies in general and our whole society. So much effort needs to be put into CYA activities, not because you're not doing your job right, but because you are liable to be subject to the whimsical judgement of stupid or ignorant people. Appearing to do the right thing is perceived as much more important that actually doing the right thing because failures of appearance tend to have much worse consequences. Look at Congress, 90% of what they do is so they appear to taking positive action on some issue, regardless of the effects it will have. And for them, it clearly works because they keep getting re-elected despite being the most consistently incompetent group of people drawing a salary in the U.S..

    • (4) Users who actually come up with relatively easy-to-remember passwords that make sense to them and are difficult to guess.

      But I guess, to make a point, one has to ignore the possible good outcome ;)

      In general though, I agree that your #s 1-3 are going to be a lot more prevalent.

    • Re: (Score:3, Insightful)

      by Shotgun ( 30919 )

      Password aging is one of those policies that sounds like it makes some degree of sense only if you don't have any understanding of human nature.

      The stereotype is that computer geeks can't get a date or fit into social situations. Why? Because they don't understand human nature. And who is in charge of setting the password policy? The geekiest guy in the organization. I see a major issue.

    • by tsalmark ( 1265778 ) on Tuesday April 13, 2010 @01:30PM (#31834914) Homepage
      Password aging does not prevent the cracking of passwords, it prevents against leaving compromised account around forever.

      Password aging made sense, once upon a time. When the biggest issue was resource theft, changing passwords every few months cleaned out the unintended access some people had, either nefariously or through chance (old unclosed account and what have you).

      Now with the speed of automated hacking tools password rotation is less than useless as a defense.

    • Re: (Score:3, Interesting)

      I've been doing columns of keys on they keyboard, It's going to be a long time before I run out, and meets most requirements. (Sometimes I hit a caps lock for the second set), Plus logging in takes almost no time at all.

      1qaz2wsx
      1qaz3edc
      2wsx3edc
      1qaz4rfv
      2wsx4rfv
      3edc4rfv
      1qaz5tgb

    • by Starteck81 ( 917280 ) on Tuesday April 13, 2010 @01:37PM (#31835062)
      I often tell people at work I'll be adding a squirrel noise requirement to the password policy next month. I always expect them to laugh but they usually just have a horrified look on their face that reads something like 'you can do that?'. I then have to clam them down and tell them I'm only kidding.
    • It seems you have forgotten the other common user behavior... sharing passwords.

      One of my reporting users had direct SQL access to a replicated and sanitized (no sensitive data) copy of our Database. He is an advanced user with plenty of reporting knowledge and we required ad-hoc reporting that did not damage/slow production.

      during a security audit, I was required to expire his password.

      the next day we had 9 tickets from 9 different users: "My access was taken away"
  • by bradley13 ( 1118935 ) on Tuesday April 13, 2010 @01:20PM (#31834682) Homepage
    Password aging is not only irritating for users, it causes them to choose even worse passwords, or to write their passwords down. If you are lucky, and they do neither of these, then it is very likely that they will use "strong-password-1", "strong-password-2".
    • Re: (Score:3, Interesting)

      I do roughly that. I use "strong-password-2.718281828459" "strong-password-3.1415926535" "strong-password-1.6180339887" and so-on and so forth. It goes from "guess the 20-character random string" to guess the constant of the month.
  • If anyone gathered metrics on such practices, I would bet that for most environments, they would find that it yields the opposite effect of what is intended.

    It makes strong passwords and lots and lots of password lists under keyboards, in text files, and on post-it notes.

    I gave a little talk [gorrie.org] at a Toorcon [toorcon.org] event a couple years ago where I included some pictures of password lists found in the wild.

    I think everyone competent knows about these things, they just choose not to say anything about it becaus
    • Re: (Score:3, Insightful)

      by John Hasler ( 414242 )

      Please cite some incidents traceable to the writing down of passwords.

      IMHO users should be instructed to write their passwords down in a little black book and to keep that book in their wallets with their money and credit cards. The company should issue the book and teach the employees how to record passwords in it, how to keep it secure, and what to do if it is stolen or lost.

  • Dupe! (Score:3, Informative)

    by howlingfrog ( 211151 ) <ajmkenyon2002&yahoo,com> on Tuesday April 13, 2010 @01:25PM (#31834776) Homepage Journal

    Less than a month ago. http://news.slashdot.org/story/10/03/16/1931214/Users-Rejecting-Security-Advice-Considered-Rational [slashdot.org]

    Kudos to the /. editors for cutting way down on the number of dupes and summary-contradicts-article stories over the past couple of years, but they're certainly not eradicated. Maybe dupe-checking should be part of slashcode--an automatic search for links and link titles that the editor (or submitter?) has to at least scroll past to post.

  • I understand the whole point behind having a secure, random password with a limited life. At the same time, I also have a piss-poor memory for random strings of ASCII characters. I don't work for a government agency, or a company with classified or even proprietary works, yet, even my mindlessly boring personal email account requires an 8 character random string with alpha and numerical characters, no runs, no common words, and no repeats. I don't use that account for ANYTHING secure or private, and if it w

  • by fattmatt ( 1042156 ) on Tuesday April 13, 2010 @01:28PM (#31834846)
    Could someone post an actual stong password you have in use?
    • Re: (Score:3, Interesting)

      by Jahava ( 946858 )

      Could someone post an actual stong password you have in use?

      I'll volunteer: 11111. I figure it's such a terrible password that brute-force software, giving humanity the benefit of the doubt, will have removed it as an option for the purposes of optimization. Thus it is the strongest password.

    • by Moryath ( 553296 )

      1...2...3...4...5.

    • by mdf356 ( 774923 )

      Compl1ant

    • Sure. The password for my Slashdot account up until last month (when it required me to change it) was gh5826@a45rx
    • Re: (Score:3, Funny)

      by Cro Magnon ( 467622 )

      My password is ********

  • The real problem with password expiration is that the benefit is not clearly understood.

    What does it combat?

    Once someone HAS the password, you are faced with closing the barn door scenario. Anything that could have been taken or accessed, likely already was. Granted you may prevent them from acquiring additional information or access, but you can't be sure that they haven't made any backdoors, even if those backdoors aren't even related to your system. With your email, I could easily construct a spear ph

  • by Midnight Thunder ( 17205 ) on Tuesday April 13, 2010 @01:30PM (#31834898) Homepage Journal

    There is one thing worse than a bad password, and that is one that needs to be written down on a post-it note.

    I see password security as an exponential curve, on a graph, reaching a certain peak and then dropping to zero. That dropping point is where the password rules become so complicated that most people would rather write the password down than try to remember it. That piece of paper suddenly became your weak point in the security model. For this reason you password policies need to focus on something that is sufficiently secure, but not so secure that it is in effect insecure.

    • Re: (Score:2, Funny)

      by cheeks5965 ( 1682996 )
      uhh... an exponential curve keeps going up. there's no maximum, no dropping down to zero. Perhaps you're thinking of a bell curve? Feel free to mod this comment down because it provides no useful content and is just kind of snarky. In fact, I should just hit the cancel button instead of the preview/submit buttons. oops...
    • Re: (Score:3, Interesting)

      by u38cg ( 607297 )
      You're thinking of something rather akin to a Laffer curve, [wikipedia.org] the idea that taxing income at 0% and 100% will both realise zero revenue (the latter since no-one would work as you'd receive no income for yourself). Similarly, if we impose no requirements whatsoever on passwords, we end up with no security, since people will leave them blank. If we demand 128 character passwords with maximum entropy, we have no security, since it will be guaranteed to be written down somewhere stupid. Somewhere, there has to
    • by UnknowingFool ( 672806 ) on Tuesday April 13, 2010 @03:01PM (#31836862)

      I used to work a government facility that had really steep requirements:

      "Passwords must be at least 15 characters long and be a combination of lowercase, uppercase, numerals, special characters, and at least one hieroglyph from the following languages: Aztec, Egyptian, or Mayan."

      I would have written down my passwords but I can't draw that well. "Is this a stork, Anubis, or a hippo?"

      They also had armed security guards wandering the halls. You had 3 chances to get the password right or they would send in the guards to blindfold you and take you away to be "liberated."

    • Re: (Score:3, Informative)

      by sootman ( 158191 )

      There is one thing worse than a bad password, and that is one that needs to be written down on a post-it note.

      Bruce Schneier* disagrees with you. [schneier.com] (About writing down passwords in general, not post-it notes in particular.)

      We're all good at securing small pieces of paper. I recommend that people write their passwords down on a small piece of paper, and keep it with their other valuable small pieces of paper: in their wallet.

  • The author makes a good point- users see the time cost of missing assignments as more damaging to their career than the benefits of following security protocol to the letter. They're probably right.

    What's interesting, I believe, is that the security employee is being fairly rational by implementing every possible security mechanism, eg CYA-type behavior. Security people tend to get a lot of stick-motivation when there's a problem but very little carrot-motivation for minimizing the intrusiveness/timewasti

  • by A Friendly Troll ( 1017492 ) on Tuesday April 13, 2010 @01:35PM (#31835010)

    How many times have you seen "the password must be between x and y characters in length and must contain blah blah"?

    I want to enter a full sentence. Like "this is my password and you won't be able to guess it, you idiot". You aren't making this possible, because you're thinking like geek programmers who use randomly-generated strings of 8-12 characters by the dozens.

    I write code and do inter-office support for my apps. Do you know how many times someone told me "I forgotz my password, halp!!11" after they were instructed to use a full sentence with a minimum of twenty-five characters? Zero. Nobody ever forgot it.

  • Password aging should automatically take into account the security of the password someone creates, via some algorithm that estimates 'guessability'

    If it's a dictionary word and number, give it three months. If it's a dictionary word, number, and two symbols, give it six months. If it's a passphrase, all regular dictionary words but not a 'standard' phrase like 'lorem Ipsum" or "The quick brown fox' leave it alone for a couple years.

    In other words - if someone is using a secure password, fuckin' reward them

  • by MrCrassic ( 994046 ) <<li.ame> <ta> <detacerped>> on Tuesday April 13, 2010 @01:45PM (#31835240) Journal

    Increased security always decreases usability. Though now that I think about it, I'm wondering: why aren't smart cards used more in corporations? Wouldn't it be convenient for people to log in with the same ID they use to get into their workplace building or floor?

    Just a thought...

  • by _bug_ ( 112702 ) on Tuesday April 13, 2010 @02:02PM (#31835630) Journal

    The biggest problem with password security is user education.

    USER. EDUCATION.

    Forget the WHY password complexity and expiring passwords is important; end-users don't care about that.

    Educate end-users on how to make passwords that are complex and easy to remember. Such a thing IS possible. For example teach users to pick a phrase or sentence and type that in, replacing all the instances of the letter E with the number 3 and to capitalize all vowels. All the user needs to remember is the phrase and the rules to make it complex. And the phrase can be something VERY easy to remember like "my daughter was born in march" which turns into "mydAught3rwAsbOrnInmArch". Maybe you leave the spaces in. Maybe you change A to 4 or L to 1. Whatever the user wants.

    It produces a complex, easy to remember password.

  • by mschuyler ( 197441 ) on Tuesday April 13, 2010 @02:12PM (#31835872) Homepage Journal

    but we just ran a cracker program on the passwd file )on Solaris at the time) and exposed about 50% of the passwords. Then we went to the affected users and said, "This is your password, right?" After the first shock passed we would say, "It's too easy. You need to change it. Next week we'll run the cracker program again." We also sent around a little tutorial on how to create good passwords by using initials of a memorized sentence (as some have suggested here) After about four runs we were down to less than 10%, and we called it good.

  • Missing the point (Score:3, Interesting)

    by DaveGod ( 703167 ) on Tuesday April 13, 2010 @02:17PM (#31835978)

    TechRepublic [com.com] covered this almost a month ago, though it still gets sidetracked (like the Boston article) in a way that exemplifies the bigger issue.

    Particularly, the point is not about password ageing, which is merely one example of how controls are often ineffective at achieving the security objectives. The bigger problem is that the usual IT security industry mantra has total disregard for all the other IT objectives. The goal (the ultimate, parent objective) of IT is to assist the organisation in achieving its objectives. IT security is just one objective for achieving that goal, but all of them are important.

    When evaluating implementing security controls do not simply consider security. You also have to consider things like productivity, expense, risk, or how it might make it harder for the company to respond to customer requirements. Failing to do this is why users’ rejection of the security advice they receive is entirely rational from an economic perspective: they are pursuing objectives and IT security appears little more than an obstacle.

  • by roc97007 ( 608802 ) on Tuesday April 13, 2010 @02:42PM (#31836464) Journal

    As a long time sysadmin, my experience has been, the more onerous the password aging algorithm, the more likely that passwords will be on yellow stickies under the keyboard.

    For instance, if your password expires monthly and you're required to pick a password with upper case, lower case, numbers and symbols, I guarantee that the majority of your users will write it down and stick it to something easily accessible.

    If you get really draconian about keeping passwords on stickies on the monitor or under the keyboard, they'll keep it in their pocketbook or stuck to the back of their cell phone, which is difficult to track and actually a worse security hole (because the building at least has physical security).

    My opinion is that password aging and password complexity rules are a managerial line item, not really a security strategy. A true security strategy is a combination of good logging, regular analysis, and tools like password breakers.

  • Hacker frustration (Score:3, Interesting)

    by JustMeHere ( 1602143 ) on Tuesday April 13, 2010 @07:28PM (#31840256)
    In the mainframe days we put in place a delay before another attempt that exponentially grew each time the password was entered incorrectly. First fail - 2 seconds delay, Second fail - 4 seconds delay, Third fail - 8 seconds...etc

A morsel of genuine history is a thing so rare as to be always valuable. -- Thomas Jefferson

Working...