TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: Do password reset policies really prevent security issues?

3 点作者 beams_of_light大约 10 年前
Per the title, I'm curious if the security-minded folks amongst us feel that forced password resets (particularly on Windows hosts) make a real difference. I understand it's not a philosophy that will change, as it's the stuff of baseline security, but am curious as to whether or not its value is perceived as high.

1 comment

smt88大约 10 年前
There was a widely-circulated study a few years ago that showed that those policies result in <i>lower</i> security.<p>The advantage of a forced reset is this: if your password has been stolen <i>but not yet used</i>, then you&#x27;re locking the thief out.<p>The disadvantage is this: the greater password strength that is required and the more times someone has to come up with a new password, the more often they&#x27;ll take shortcuts. Those shortcuts result in easier brute-force or heuristic attacks.<p>So if you look at the advantage, it&#x27;s very small and potentially non-existent. It&#x27;s rare to steal a password from a high-value target and then sit on it, especially for as long as a few months.<p>Looking at the disadvantage, it&#x27;s actually very high, and it makes it easier to steal passwords in the first place.
评论 #9169350 未加载