{"id":138338,"date":"2015-09-11T08:53:16","date_gmt":"2015-09-11T06:53:16","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=138338"},"modified":"2015-09-11T08:54:43","modified_gmt":"2015-09-11T06:54:43","slug":"new-password-security-rules-may-surprise-users","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/138338-new-password-security-rules-may-surprise-users.html","title":{"rendered":"New password security rules may surprise users"},"content":{"rendered":"<p>The government of the United Kingdom recently released new guidelines for passwords, which said that complex password policies and changing a password regularly do not have much value.<\/p>\n<p>When every system needs a different password, the complexity settings for each system are set high and password changes are enforced frequently &#8211; the outcome is not better security.<\/p>\n<p>\u201cThrough research, in collaboration with the Research Institute in the Science of Cyber Security, we&#8217;ve learnt about how trying to make passwords &#8220;more secure&#8221; means systems end up less secure,\u201d it\u00a0said.<\/p>\n<p>\u201cWhen we&#8217;re overloaded with passwords, we all end up &#8220;breaking the rules&#8221;: we use the same passwords across different systems; we use coping strategies to make passwords more memorable (and thus more easily guessed), and we store passwords insecurely.\u201d<\/p>\n<p>Worst of all, making password policies complex doesn&#8217;t stop attacks. Attackers who have stolen a password database &#8211; even if hashed and salted &#8211; can generally brute force the majority of the passwords.<\/p>\n<p>Attackers who only get a few tries at guessing passwords (such as with a well-designed online service, or enterprise IT network with throttling and lockout) will be stopped by a fairly short password.<\/p>\n<p>The majority of password policies are in the middle of this &#8211; they give us passwords that are too short to prevent brute force attacks, but that are much more complicated than they need to be.<\/p>\n<p>&#8220;The result is that we&#8217;re asking users to put in more work remembering complicated passwords, for no actual extra security benefit.&#8221;<\/p>\n<p>The image below provides an overview on password security from the UK government.<\/p>\n<div id=\"attachment_138346\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><a  data-lightbox=\"post-image\" href=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/09\/Password-security.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-138346\" class=\"wp-image-138346\" src=\"http:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/09\/Password-security.png\" alt=\"Password security\" width=\"630\" height=\"393\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/09\/Password-security.png 2000w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2015\/09\/Password-security-640x400.png 640w\" sizes=\"(max-width: 630px) 100vw, 630px\" \/><\/a><p id=\"caption-attachment-138346\" class=\"wp-caption-text\">Password security<\/p><\/div>\n<h3 class=\"my-4\">More on passwords<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/137066-this-is-what-your-password-should-look-like.html\"><strong>This is what your password should look like<\/strong><\/a><\/p>\n<p><strong><a href=\"http:\/\/mybroadband.co.za\/news\/security\/124848-worst-500-passwords-in-the-world.html\">Worst 500 passwords in the world<\/a><\/strong><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/117196-worst-online-passwords-in-the-world.html\"><strong>Worst online passwords in the world<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Making all password policies complex doesn&#8217;t stop attacks, said the United Kingdom&#8217;s government.<\/p>\n","protected":false},"author":23,"featured_media":124874,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[36,3676],"class_list":["post-138338","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-active","tag-passwords"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/138338"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=138338"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/138338\/revisions"}],"predecessor-version":[{"id":138342,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/138338\/revisions\/138342"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/124874"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=138338"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=138338"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=138338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}