Not according to Lorrie Cranor, chief technologist of the Federal Trade Commission (FTC), who created something of a media buzz earlier this year when she declared in a blog post that it was,“time to rethink mandatory password changes.”
She gave a在BSides安全会议上发表主题演讲in Las Vegas earlier this month making the same point.
但该消息并不新鲜 - 她一直鼓吹了一段时间。Cranor,谁前她搬到美国联邦贸易委员会是计算机科学与工程和公共政策在卡内基 - 梅隆大学的教授,给了一个TED talkon it more than two years ago.
She cited research suggesting that, “users who are required to change their passwords frequently select weaker passwords to begin with, and then change them in predictable ways that attackers can guess easily.”
This, she said, was demonstrated more than six years ago in a 2009-2010 study at the University of North Carolina at Chapel Hill. Researchers, using passwords of more than 10,000 defunct accounts of former students, faculty and staff, found it much easier to破解的新密码,如果他们破获一老一, since users tended create a new password with a minor tweak of the old one.
这些调整包括改变一个小写字母to upper case, substituting a number for a letter, such as a “3” for an “e,” or simply adding a couple of letters or numbers to the end of the previous password.
Cranor说,研究人员发现,如果他们知道以前的密码,他们可以猜测少于五次尝试新的。谁也偷了哈希密码文件,黑客就能够在三秒钟内猜测新的 - 这是与2009年的技术。
And the National Institute of Standards and Technology (NIST), in a draft publication from April 2009 (although it was marked “Retired” this past April), saidpassword expiration policies frequently frustrate users, who then, “tend to choose weak passwords and use the same few passwords for many accounts.”
不足为奇的是,攻击者非常了解这些漏洞。最新的Verizon Data Breach Incident Report (DBIR)发现所有数据泄露的63%涉及使用被盗,弱或默认密码。
由禁卫军本月初公布的一份报告表明,有四列前在网络杀伤链五项活动无关的恶意软件,但随着stolen credentials,由于一些事情,如弱域用户密码和存储明文密码。
Zach Lanier, director of research at Cylance, cites Apple’s TouchID and Google’s Project Abacus as mobile options to wean users off passwords, but said passwords are obviously, “still around, and they’re likely to be for a bit longer. It’s just that they’re so ‘standard’ for people and enterprises, and have been for so long, that it’s really hard to make them completely disappear.”
In the interim, he said, organizations can improve their password security through a combination of employee training and, “actively testing their authentication mechanisms and auditing users’ passwords – cracking them – whether it’s through internal infosec teams or external firms. In my opinion, it should be both,” he said. “This can give the organization a better idea of where things are broken, from people to technology.”
McDowell agrees that education is, “a laudable endeavor, especially to help users avoid falling victim tophishing和/或social engineering攻击“。但他表示,“共享密钥”身份验证模式很容易受到攻击的太多形式 - 不只是社会工程 - 因此,以尽快消除它们的需要。
Tom Pendergast, chief strategist, Security, Privacy & Compliance, at MediaPro, said organizations can and should have much more rigorous password policies. “Current policies set the bar far too low for complexity in passwords and don’t require multi-factor authentication, acknowledged as the best commonly-available solution,” he said.
Lanier agreed. “There are some really awful organizations, sites or services that can’t seem to move past the year 1998 with authentication,” he said.
Pendergast said he sees the same thing. “There is plenty of existing technology designed specifically to prevent users from repeating passwords, using common passwords, and enforcing password rules. A surprising number of companies don’t use these basic password reinforcement functions,” he said.
尼尔指出,“password managers are, of course, a huge boon for generating complex passwords without the fuss of having to remember them or write them on a Stickie note. This at least reduces the risk that a person might serialize their password choices. Certainly not a panacea, but for the average person, it’s a great idea.”
[ RELATED:如何评价密码管理]
All agree that the weaknesses of human nature mean it would be better to move beyond passwords. But, as McDowell notes, human nature also requires that whatever replaces passwords must be, “easier to use than passwords alone.
Until then, Lanier said, organizations should, at a minimum, not rely on passwords alone.
“At the very least, if/when that poor password gets cracked or guessed, two-factor authentication raises the bar for the attacker,” he said.
这个故事,“定期更改密码使事情变得更糟”最初发表CSO .