The Man Who Wrote the Password Rules Regrets Doing So (gizmodo.com)
New submitter cdreimer writes: According to a report in The Wall Street Journal (Warning: source may be paywalled, alternative source), the author behind the U.S. government's password requirements regrets wasting our time on changing passwords so often. From the report: "The man who wrote the book on password management has a confession to make: He blew it. Back in 2003, as a midlevel manager at the National Institute of Standards and Technology, Bill Burr was the author of 'NIST Special Publication 800-63. Appendix A.' The 8-page primer advised people to protect their accounts by inventing awkward new words rife with obscure characters, capital letters and numbers -- and to change them regularly. The document became a sort of Hammurabi Code of passwords, the go-to guide for federal agencies, universities and large companies looking for a set of password-setting rules to follow. The problem is the advice ended up largely incorrect, Mr. Burr says. Change your password every 90 days? Most people make minor changes that are easy to guess, he laments. Changing Pa55word!1 to Pa55word!2 doesn't keep the hackers at bay. Also off the mark: demanding a letter, number, uppercase letter and special character such as an exclamation point or question mark -- a finger-twisting requirement." "Much of what I did I now regret," Bill Burr told The Wall Street Journal. "In the end, [the list of guidelines] was probably too complicated for a lot of folks to understand very well, and the truth is, it was barking up the wrong tree."
I have to say that's really cool of him to come out and say that. Awesome for somebody to be able to admit they are wrong, as we are all wrong at different times. Way to go!
Just because I can hook a shark from a boat, I do no offer to wrestle it in the water.
My university recently instituted this retarded system that we have to change every 90 days.
And they remember the last 5 or so hashes (one can only hope they don't remember the actual password), so you can't even switch back and forth.
Absolute bullshit.
I remember my dad just changed his every month and he just had MMYY at the end of every password.
LONG PASSWORDS.
The exponent of the equation (alphabet_size)^(length of password) matters MUCH more than the mantissa.
Put another character on the end of an alphanumeric password and you're doing more than selecting even the weirdest of keyboard-typeable symbols.
And the change-your-password-every-X-days was always junk and just provide a route for social engineering of the password reset process on a pre-determined schedule. If your password hasn't been compromised in a reasonable time, it's not going to be compromised. If your system LETS you try trillions of passwords, it's game over whether you change every week or not.
Those who require passwords really ought to take a look at it.
https://xkcd.com/936/
This egomaniac isn't responsible, password rules meeting or exceeding his claim go back at least two decades for Commercial companies, and longer for "Government" (especially DOD). I have a policy from 1995 that I wrote for the company I worked for at the time.
Password enforcement was a constant problem 20-30 years ago, but we all had policies.
The short duration of a password was not some arbitrary number based on "mah ego", it was based on a majority of systems which could not handle a password longer than 8 characters.
I didn't invent the password policy, but by this claim I sure as hell could.
Oh, and password policies are as important today as they were back then. Go ahead and claim your fingerprints are fool proof!
-The wise argue that there are few absolutes, the fool argues that there are no probabilities.
My pet annoyance are those sites that do not clearly state what their particular requirement is, clearly, up front. So it only tells you after you've entered something you think may be acceptable, and you've then lost that train of thought and are forced to figure out something new.
Here is your current password: Pzssw0rd1
(Don't worry - while you'll see your password in plain text there, all the other Slashdotters will see a string of asterisks like this: *********)
#DeleteChrome
This is not a news to many sysadmins. Some of our managers even get it as well.
None of that matters in the face of regulatory compliance.
The Daddy casts sleep on the Baby. The Baby resists!
I'm more annoyed when sites require passwords that aren't in line with the kind of data they're holding. I don't want to have to remember a banking-safe password when I'm trying to log into a fart jokes website.
I swear to God...I swear to God! That is NOT how you treat your human!
...also suggested using cruise ships for population control.
Sig ?
I have had to fight our auditors every year for decades about stupid password ageing rules. I refused to implement them and said it would LOWER security while simultaneously pissing off users and lowering productivity. Each year I added more references to articles from people who agreed with me, just in case.
Maybe now they will finally believe me?
5 years ago, our client insisted that we implement this sort of mischief on one site, with a 30-day change rule. One of the requirements was to check that the new password was not previously used or too similar to a previously-used PW.
"How does that work when you also tell us we cannot save the PW in plain text?"
To their credit, they admitted that it wasn't possible to comply with all the rules. But they have not yet relented on the 30 day change rule.
Which bit them big time during one of their security sweeps - the PW for the scanner's account "expired" part way through the testing. The subsequent lock-out for excessive failed login attempts was then interpreted as "server becomes unresponsive if excessive characters are injected at login." (we'll accept up to 32MB for passwords)
I strongly suspect that one way to measure how onerous the password policy is in a particular environment is to go through the office flipping up keyboards. The metric would be as a percentage of yellow stickies with passwords stuck underneath. You could weight the metric by the size of the penalty for writing down your password.
Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
Or sites where they accept an unlimited length in the setup but silently truncates to some arbitrary length and then when on the login page they accept an unlimited length again but this time compares your entered password with the truncated one and you get a mismatch even with copy+paste. Have stumbled on a few of those.
Which means that you work system is storing your password in a recoverable form which is an even worse situation than having meaningless complex rules about what a password can look like.
HIs password policies suck. No wonder he changed careers.
"The agriculture ministry is not in charge of Gundam" - Japanese ministry official.
Those of us interested in tracking every detail of your single-purchase behaviors...then selling that info to another entity...strongly disagree that there isn't a need to force you to voluntarily register and create an account. Despite your tone indicating that you disagree with this practice, our records clearly show you clicked "I agree."
Yet more annoying is sites that prevent you from Control-V paste or middle-click paste. Come on! I want to be able to generate a 32 or 64 character gobbledygook password in KeePass and just paste it in there.
Some sites screw it up and prevent either Control-V or middle-click, but not both. But those are rare. Seriously, web developers, it doesn't help anybody to prevent pasting into a password field.
The worst was one financial-related site that I had to use that not only did not allow you paste into the password field, it would not even let you type into the password field. It would present an on-screen keyboard (using JavaScript) with the letters and numbers all scrambled around. Take about practically forcing people to write down their passwords. (To me a decent password is one that I can only enter by muscle memory; as in, I could not actually tell you the password itself even if my life depended on it).