Re: minimum number of days between password change



On 11/01/2010 04:45 PM, Jesús M. Navarro wrote:
Hi, Ron:

On Monday 01 November 2010 18:49:01 Ron Johnson wrote:
[...]
If someone learns my password on day 2, they have full access to my
account for 74 days, or I must beg for SysAdmin help?

"Minimum number of days" isn't a very bright idea.

It is, for a low minimum number.

The rationale is to avoid the user reusing passwords: Ok, so my password is
12345678 and I must change it now? Let's do it: 87654321; but immediately I
change back again.


The way to do it is to have a record in your password db of the hashes of each user's last N passwords.

So if the minimum change time is about a week, it takes about the same effort
to learn the new password than to change it back.


You're Doing It Wrong if you use "minimum days" to avoid password reuse.

--
Seek truth from facts.


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx
Archive: http://lists.debian.org/4CCF4D3F.3000603@xxxxxxx



Relevant Pages

  • Re: minimum number of days between password change
    ... account for 74 days, or I must beg for SysAdmin help? ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: minimum number of days between password change
    ... On Tuesday 02 November 2010 00:29:03 Ron Johnson wrote: ... or I must beg for SysAdmin help? ... You're Doing It Wrong if you use "minimum days" to avoid password reuse. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: minimum number of days between password change
    ... On Monday 01 November 2010 18:49:01 Ron Johnson wrote: ... account for 74 days, or I must beg for SysAdmin help? ... The rationale is to avoid the user reusing passwords: ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
    (Debian-User)
  • RE: Emails [SEC=UNCLASSIFIED]
    ... work (therefore had no access to my WORK email account), and frankly, ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ... Trouble? ... Organisation and is subject to the jurisdiction of section 70 of the ...
    (Debian-User)
  • Re: OE newsgroup .dbx file name BUG
    ... subscribe the same newsgroup "szGroupName" under news ... Subscribe the newsgroup "szGroupName" under news account A ... Unsubscribe one of them, close OE, the "szGroupName.dbx" file is ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)