DATA DOCTORS

The downside to mandatory password changes

Aug 11, 2016, 5:57 PM

(AP Photo/Damian Dovarganes, File)...

(AP Photo/Damian Dovarganes, File)

(AP Photo/Damian Dovarganes, File)

Q: Is requiring users to regularly change their passwords a good idea?

Passwords are often referred to as the weakest link in security by many cybersecurity professionals, primarily because of the human element.

Most systems require users to include upper and lower case letters, at least one number, and in some cases, at least one special character.

Human behavior is very predictable by sophisticated hackers and when left to their own abilities, the average user will create weak passwords that are easy to break because it’s just not an intuitive process.

With this in mind, many researchers are suggesting that forcing users to regularly change their passwords, which is common in corporate settings, can actually encourage the creation of weaker passwords.

Creating strong passwords for each of your accounts is hard enough, so forcing users to regularly come up with new ones tends to create an environment where human nature takes over.

It makes technical sense

From a purely technical viewpoint, regularly changing passwords makes sense, as it renders compromised passwords useless, but it ignores the reality that humans are involved.

Several researchers have published studies over the years warning of the unintended consequences of regularly forced password changes and one of the more prominent figures to speak out on this common practice is the Chief Technologist for the FTC Lorrie Cranor.

Her FTC blog titled “Time to rethink mandatory password changes” points to a UNC research paper that showed users tend to use predictable patterns they call “transformations” (like just adding the next number) when regularly required to change passwords.

Cyber thieves know that this behavior is common and have been using password cracking tools that can guess the highest probability for new passwords based on old passwords that have been compromised.

This common human behavior can render the technical benefits of forced password changes useless because cracking the “new password” can actually be made easier over time through pattern recognition.

When you should change passwords

Large scale data compromises seem to be in the news just about every week, and whenever a company that you do business with has been compromised, you should immediately change your password.

Likewise, if your company knows that an outsider may have gained access to their network, forcing everyone to change their passwords is a no-brainer.

If you discover your computer has been infected with malware, especially since often times one infection can lead to many others, you should change your online passwords from another computer or after your computer has been disinfected as a precaution.

Better security measures

Since data breaches and malware are a fact of life these days, assuming that your password is going to be compromised at some point is a good strategy.

Activating two-factor authentication or login approvals (How to setup password fraud alerts) on all of your online accounts provides you with an extra layer of protection when the inevitable occurs.

Virtually every major online service offers this protection and it’s far more effective than regularly changing your passwords because it prevents thieves from gaining access even if they do steal your passwords.

Data Doctors

Patrick Mahomes #15 and head coach Andy Reid of the Kansas City Chiefs are recorded on a phone as t...

Data Doctors

Handy tech tips all Valley residents should use to find lost phones in a snap

Q: My phone went missing, and I haven’t been able to locate it using the Find My service, so what should I do next?

5 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are tips for freeing up Google storage space

Google provides a generous amount of free online storage but it can fill up quickly depending on how many of its resources you use.

12 days ago

Discover how to assess, estimate, and shop for the right battery pack with this concise guide. (Pex...

Data Doctors

Here is everything you need to know for testing and buying battery banks

Discover how to assess, estimate and shop for the right battery pack with this concise guide.

19 days ago

(Pexels Photo)...

Ken Colburn, Data Doctors

Here are the truly free smartphone video editing apps

The processing power on our smartphones has grown exponentially, allowing anyone to perform sophisticated video editing easily.

25 days ago

Google Maps app....

Data Doctors

How to rediscover places visited years ago on Google maps

Whether you're an Android or iOS user, or prefer accessing Google Maps on your computer, you'll find step-by-step instructions to unlock your travel memories effortlessly.

1 month ago

(Photo by Michael Bocchieri/Getty Images)...

Ken Colburn, Data Doctors

Here’s how to calculate your bandwidth needs

When searching for an alternative internet service provider, here are some tips on how to know how much bandwidth is needed.

1 month ago

Sponsored Articles

...

Midwestern University

Midwestern University Clinics: transforming health care in the valley

Midwestern University, long a fixture of comprehensive health care education in the West Valley, is also a recognized leader in community health care.

...

Fiesta Bowl Foundation

The 51st annual Vrbo Fiesta Bowl Parade is excitingly upon us

The 51st annual Vrbo Fiesta Bowl Parade presented by Lerner & Rowe is upon us! The attraction honors Arizona and the history of the game.

(KTAR News Graphic)...

Boys & Girls Clubs

KTAR launches online holiday auction benefitting Boys & Girls Clubs of the Valley

KTAR is teaming up with The Boys & Girls Clubs of the Valley for a holiday auction benefitting thousands of Valley kids.

The downside to mandatory password changes