Thinking of a secure password is hard, so demanding a user change it every 60 days fills many with dread and leads to weaker security. Microsoft has realized this and decided to remove default password expiry as a security baseline feature in Windows 10.
When organizations deploy Windows 10 to tens, hundreds, or even thousands of employees, default security out the box is very important. That's why Microsoft provides Windows security baselines, which consist of a group of Microsoft-recommended configuration settings that can be relied upon to provide a more secure operating system.
As part of the baseline, Microsoft in the past stipulated a 60-day password expiration policy, which meant every user was forced to change their password every couple of months (unless an organization changed the configuration). As Ars Technica reports, with the release of Windows 10 v1903, password expiration is being dropped from the baseline because it's actually detrimental to security.
Microsoft explains in its latest draft security baseline for Windows that, "When humans are forced to change their passwords, too often they'll make a small and predictable alteration to their existing passwords, and/or forget their new passwords ... Periodic password expiration is a defense only against the probability that a password (or hash) will be stolen during its validity interval and will be used by an unauthorized entity. If a password is never stolen, there's no need to expire it."
Microsoft also points out that if a password is stolen, the thief has up to 60 days to use it based on this expiration policy, which is ample time to gain entry to a system and cause chaos. So on every level, password expiration simply doesn't work, which is why it's disappearing.
Passwords still need to meet a minimum length requirement, be complex enough so as not to be easily guessed, not have been used before, and stored securely. It may still be the case that individual organizations enforce their own expiration policy, but it seems likely the demand for a new password every few months will impact far fewer workers going forward, and that's a good thing for both their sanity and security.
Copyright © 2023 Powered by
Microsoft realizes password expiration is poor security-声闻过情网
sitemap
文章
8
浏览
3
获赞
1
The summoning circle meme calls upon your deepest, darkest desires
If you could request anyone and anything, what would it be?The new "summoning circle" meme has TwittNew York Times code stolen and leaked on 4Chan — Wordle apparently included
Can't get enough of Wordle? Try Mashable's free version now TWatch the controversial speech slamming Trump in UK Parliament
John Bercow, the Speaker of the UK's House of Commons, has caused mixed reactions for saying that PrWWDC 2024: Apple announces new Safari with Highlights and 'distraction
Safari is getting an AI-powered revamp. Apple didn't forget about its browser amidst the slew of AIMeghan and Harry reveal their newborn son's name
The Duke and Duchess of Sussex have announced their newborn son's name: Archie Harrison Mountbatten-The LGBTQ community is coming to march and werk on Washington
Hundreds of members of the LBGTQ community twerked and booty bounced their way to a dance party outsiOS 18: How to lock and hide your iPhone apps
Among the iOS 18 features Apple announced at WWDC 2024, the ability to lock and hide apps was a stanFiona Apple debuts catchy anti
Fiona Apple doesn't like Donald Trump, that much she's made clear. Her musical resistance started wiThe 'Car Alarm Challenge' is here to shatter everyone's eardrums
We regret to inform you that one of the most annoying sounds in the world has inspired an internet cAmazon deals of the day: LG CordZero All
Amazon deals of the day at a glance: OUR TOP PICKI tested Rabbit R1 vs. Meta AI: The winning AI assistant will surprise you
Table of ContentsTable of ContentsLet's do a Rabbit R1 vs. Meta AI (via Ray-Ban Meta Smart Glasses)Where to pre
UPDATE: May. 10, 2024, 10:15 a.m. EDT This story has been updated with new preorder listings and off'SighSwoon' merges self
Scrolling through @SighSwoon on Instagram is the equivalent of picking up a mysterious book at a thrMan dancing his heart out instantly becomes the best new meme
The best part of any wedding is on the dance floor.Reddit's r/pics was recently blessed with this phYouTube is removing North Korean content and no one knows why
UPDATE: Jan. 25, 2017, 1:45 p.m. SGT This piece has been updated with comments from Google and Trusz