Microsoft Says Forced Password Resets Don’t Improve Security

Microsoft Says Forced Password Resets Don’t Improve Security

Anyone who has spent more than a few weeks working in a corporate environment has dealt with the frustration of mandatory password changes. However, those days may finally be coming to an end. In a recent blog post, Microsoft admitted that compulsory password changes don’t enhance security and may actually make enterprise networks less secure.

For decades, the baseline password practices Microsoft provided to customers suggested forcing employees to change their passwords every 60 days. According to Microsoft’s Aaron Margosis, that technique is an “ancient and obsolete mitigation of very low value.” It comes from an era in which people might share passwords, and in time, a password might leak out of the organization. Today’s password breaches happen at the speed of light as malicious actors steal data and use GPUs to guess passwords. Assuming that a password is stolen, isn’t 60 days a rather long time to allow the thief to use it anyway? Anyone who’s going to do real damage will have done it long before the password reset rolls around.

When you force users to change passwords frequently, they’re likely to choose passwords that are easy to remember. Research shows that such passwords are probably the easiest to crack in the event someone steals a hashed database and unleashes an army of GPUs on it. For example, people use dictionary words with numbers substituted for similar looking letters. If you make them change that password, they’ll probably just make predictable changes that are just as easy to crack.

Microsoft Says Forced Password Resets Don’t Improve Security

Margosis says that implementing requirements like banned-password lists, multi-factor authentication, detection of password-guessing attacks, and detection of anomalous login attempts make forced password resets obsolete. Passwords are inherently problematic for security, so making people choose more bad passwords isn’t the best approach. Margosis points out that Microsoft is not changing its guidelines on password length, complexity, or history. The most robust passwords are randomly generated, and the longer they are, the better.

While Microsoft will stop telling organizations to force password resets, it won’t be taking its own advice right away. The password reset timer in Windows Server products is still 42 days. It wouldn’t be surprising if Microsoft changes that default in future versions, though. Nevertheless, IT workers who want to do away with tedious and unnecessary password resets will have something to show higher-ups to help make their case.

Continue reading

Nvidia GeForce RTX 3060 Ti Launches Dec. 2, but Good Luck Getting One
Nvidia GeForce RTX 3060 Ti Launches Dec. 2, but Good Luck Getting One

The RTX 3060 Ti goes on sale tomorrow for a mere $399—it might even be affordable after the obscene reseller markup!

The US Air Force Quietly Admits the F-35 Is a Failure
The US Air Force Quietly Admits the F-35 Is a Failure

The Air Force has finally admitted that the F-35 is not the aircraft the military hoped it would be, though we doubt Ferrari would appreciate being compared with the F-35.

Star Citizen Devs Angry, Forced to Work Through Life-Threatening Texas Storm
Star Citizen Devs Angry, Forced to Work Through Life-Threatening Texas Storm

Multiple Cloud Imperium Games employees have spoken out against their employer over how they were treated during the 2021 Texas snowstorm.

Nvidia Doubles GeForce Now Subscription Price to $10 Per Month
Nvidia Doubles GeForce Now Subscription Price to $10 Per Month

Nvidia is increasing the paid tier from $5 per month to $10. This brings it more in-line with other streaming platforms, but the price was Nvidia's big advantage until now.