Daily using/supporting

Get Firefox browser!
Get Thunderbird!
Get Opera browser!
Get The Gimp!
Get Inkscape!
Get LibreOffice!
Get Videolan!
Get Linux!
Get Mandriva!
Get Joomla!
Hacker Emblem

Archives

Which topics would you like us to cover more?

Latest comments

Latest tweets

about 3 days ago Social engineering from India #dib0 http://t.co/ajjp43WkVS
about 12 days ago @unwoman Got the kickstarter Uncovered Vol. 2 today! Thank you! I love it! http://t.co/x0Tzovtq8u
about 14 days ago A query is running #dib0 http://t.co/cRZ8Dd3nVp
15 Apr 2013 Locally save attachments from Oulook using VBScript #dib0 http://t.co/l6RhWQsvFL
1 Apr 2013 Publishing Outlook calendar for use in Google calendar through http://t.co/sfh5eNxGXM #dib0 http://t.co/IzWNPlaqNA
21 Mar 2013 http://t.co/j3B0kSLGkM Really interesting article. The church of pirates. Gods preferential option for the poor in the broadest sense.
14 Mar 2013 Happy Pi-day! And this is what's wrong with it... funny, but true. http://t.co/A8GIB8fugC
14 Mar 2013 Hey guys @piwik ! Just looking at my site stats. I love the new page overlay feature. Well done! :-)
3 Mar 2013 Really funny! The Burning Hearts Revolution: How Sesame Street is Undermining Biblical Values http://t.co/z8XFk5P4d3
26 Feb 2013 Recursively check and correct mp3 files in Linux #dib0 http://t.co/U3nzOuWzWM
26 Feb 2013 Haha! Met zo'n antwoord een terechte reactie! http://t.co/NYXIb27aP5 via @snippers
20 Feb 2013 Create random password with C#, Java and PHP #dib0 http://t.co/WgF7DtcT
Home Architecture, security and coding Required password change policy - still a good idea?
Required password change policy - still a good idea?
Written by Division by Zero   
Wednesday, 04 August 2010 13:34

Yesterday my mother in law asked me to help her. She couldn't log in to the web-application she needed for her work. Turns out that the password policy requires that the password must change every month. After some explaining and demonstrating the problem was solved.
Master lock
It is a good idea to change your passwords after a certain amount of time. It is more secure: if you ever lose your password, someone else can only use it for a certain amount of time. On the other hand: If there weren't any password policies that would require us to change our passwords, would we change them? I think not. I use a lot of password, have a lot of accounts (too many!), and can't remember all of them. For example: I need at least 4 different passwords to do my job. The ones I type in every day I can remember, but having to change them annoys me. The logical thing to do, like a lot of my colleagues do, is number them or use the number of the month in which the password is changed. But this creates an unsafe, guessable, password. It is impossible to have a safe password and remember it after every change. People will write it down or use e less safe password, which makes the whole thing less secure. And password safes aren't applicable everywhere.

Wouldn't it be a better idea if the password policy doesn't require you to change your password, but requires a certain strength level? My password is like the key to my house. I have two locks to enter, so I need two keys. Both locks and keys have a certain level of strength to resist a break in attempt. I guard my keys quite well, because I don't want anyone to break in to my house. I am able to think of a strong password I can remember. If I know the risks of breaking in, I will protect my password. Of course we need other security measures the keep criminals from stealing my password, but these are always necessary.

I'm thinking that a required password changes doesn't increase security, but keeps security on the same level or even decreases it. Any thoughts, anyone?

 

Add comment


Security code
Refresh

If the human brain was simple enough for us to understand we'd be so simple we couldn't understand. - Unknown


© 2009 - 2013, Division by Zero

Template based on the empire template by joomlashack 

 Creative Commons License
This work by Division by Zero is licensed under a Creative Commons Attribution-Noncommercial-Share Alike 3.0 Netherlands License.