Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Forced changing of passwords every x months is pretty common in the workplace, especially if the company is Windows based.

The problem is it's so easy to make your passwords be <root>+1, then <root>+2, etc. I've worked at places that detected that pattern and didn't allow it, so I would just hold down the shift key and iterate anyway, yielding <root>+!, then <root>+@, <root>+#, etc.

So even forcing your users to change their passwords will most likely cause them to find a way around it. IMO the problem is passwords are inherently a flawed concept. We need something better. Hopefully biometrics can truly solve this problem one day.



biometrics will still require a fallback for any general purpose system. For example, you can't require fingerprints because there's a chance you'll get users without fingers. You can't require retinal scans because there's a chance you'll get users without eyes. You could probably ask the user to spit and check their DNA, but there's a higher chance of spreading disease that way. Eventually you'll need a fallback of a password/key, and if I were an attacker, I'd always attack the fallback (it's often the least well thought out part of auth).


Also, fingerprints erode with certain professions and are susceptible to environmental things like sweat and dirt. Retinas change with disease and pregnancy. DNA is far too expensive to use daily, unless you restrict their accuracy to populations.


...and biometrics are not authentication, just simple access control. Many, many of us have the same biometrics - its a hash. Its hardly better than a garage door opener.


There's always a really simple solution to those rules: post-its.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: