Thinking of a secure password is hard, so demanding a user change it every 60 days fills many with dread and leads to weaker security. Microsoft has realized this and decided to remove default password expiry as a security baseline feature in Windows 10.
When organizations deploy Windows 10 to tens, hundreds, or even thousands of employees, default security out the box is very important. That's why Microsoft provides Windows security baselines, which consist of a group of Microsoft-recommended configuration settings that can be relied upon to provide a more secure operating system.
As part of the baseline, Microsoft in the past stipulated a 60-day password expiration policy, which meant every user was forced to change their password every couple of months (unless an organization changed the configuration). As Ars Technica reports, with the release of Windows 10 v1903, password expiration is being dropped from the baseline because it's actually detrimental to security.
Microsoft explains in its latest draft security baseline for Windows that, "When humans are forced to change their passwords, too often they'll make a small and predictable alteration to their existing passwords, and/or forget their new passwords ... Periodic password expiration is a defense only against the probability that a password (or hash) will be stolen during its validity interval and will be used by an unauthorized entity. If a password is never stolen, there's no need to expire it."
Microsoft also points out that if a password is stolen, the thief has up to 60 days to use it based on this expiration policy, which is ample time to gain entry to a system and cause chaos. So on every level, password expiration simply doesn't work, which is why it's disappearing.
Passwords still need to meet a minimum length requirement, be complex enough so as not to be easily guessed, not have been used before, and stored securely. It may still be the case that individual organizations enforce their own expiration policy, but it seems likely the demand for a new password every few months will impact far fewer workers going forward, and that's a good thing for both their sanity and security.
Copyright © 2023 Powered by
Microsoft realizes password expiration is poor security-坐而论道网
sitemap
文章
1
浏览
26
获赞
2
New York City blackouts always bring the wildest photos
It's rare to catch New York City, the so-called "city that never sleeps," at rest. Not even SaturdayWinter storm warnings: How to see online if more snow is heading your way
A massive winter storm is blanketing large swaths of the Southern U.S. in snow and ice, leaving millBest laptop deal: Save 48% on the Samsung Galaxy Book4 Pro at Amazon
SAVE $645.38:As of Feb. 18, get the Samsung Galaxy Book4 Pro (Intel Core 5 Ultra, 16GB RAM, 512GB SSEarth's mini moon could be a chunk of the big moon, scientists say
A mini moonthat will bid farewell to Earth soon may in fact be a small hunk of the big moon— tTrump's racist Baltimore tweets part of a pattern, CNN anchor explains
Donald Trump started off his Saturday morning with a mean-spirited and racist attack on CongressmanBest home security deal: Save $242.33 on a 4
SAVE 49%:A 4-pack of the Arlo Pro 5S Spotlight Camera is on sale at Amazon for just $249.99, down frThe long, thorny history of Boeing's Starliner spaceship
If someone had told NASAa decade ago that SpaceXwould build a new ride for astronauts to get to theReddit paywalls to hit this year as paid subreddits confirmed
Paywalled subreddits are coming this year, confirmed by Reddit CEO Steve Huffman. In a prerecorded vBig Tech readies itself for two very distinct grillings at Senate hearing
Get ready for some Senate questioning whiplash. On Wednesday morning, the CEOs of Twitter, Facebook,NASA rover finds major surprise on Mars — and scientists are excited
NASA has used a number of eyebrow-raising words to describe their new Martian find: "fascinating," "NASA rover finds major surprise on Mars — and scientists are excited
NASA has used a number of eyebrow-raising words to describe their new Martian find: "fascinating," "Best speaker deal: Take 30% off the Ultimate Ears Wonderboom 4
SAVE $30:The Ultimate Ears Wonderboom 4 speaker is on sale at Amazon for $69.99, down from the usualSubway riders befriended a cute little bug on the train
Bugs on the New York City subway system rarely get the star treatment, but one lucky insect got vaulBest beauty deal: Save 30% on the Shark FlexStyle
SAVE $90:The Shark FlexStyle air styling and drying system is on sale at Amazon for $209.99, down frReddit paywalls to hit this year as paid subreddits confirmed
Paywalled subreddits are coming this year, confirmed by Reddit CEO Steve Huffman. In a prerecorded v