惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
J
Java Code Geeks
Martin Fowler
Martin Fowler
Microsoft Azure Blog
Microsoft Azure Blog
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
人人都是产品经理
人人都是产品经理
有赞技术团队
有赞技术团队
爱范儿
爱范儿
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI
博客园 - 【当耐特】
Y
Y Combinator Blog
Last Week in AI
Last Week in AI
MongoDB | Blog
MongoDB | Blog
G
Google Developers Blog
博客园 - 三生石上(FineUI控件)
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
大猫的无限游戏
大猫的无限游戏
罗磊的独立博客
The Cloudflare Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
V
V2EX
博客园 - 司徒正美

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops Understanding GRC: How to Navigate Risks and Compliance Standards The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP)
Passwords: Our First Line of Defense
BHIS · 2019-12-04 · via Black Hills Information Security, Inc.

, , , , , ,

Darin Roberts //

“Why do you recommend a 15-character password policy when (name your favorite policy here) recommends only 8-character minimum passwords?” I have had this question posed to me a couple of times in the very recent past.  

There were 2 separate policies that were shown to me when asking these questions. First was the NIST policy.  From the NIST 800-63 guidelines, it says that “memorized secrets [are] to be at least 8 characters in length.”  Memorized secrets are defined to include passwords. The NIST guidelines were recently updated, but the password minimum length remains at 8 characters. Taken from https://blog.didierstevens.com/2017/02/28/password-history-analysis/.

The other policy was the policy for Microsoft Office 365.  This policy states that one recommendation “for keeping your organization as secure as possible” is to “maintain an 8-character minimum length requirement (longer isn’t necessarily better).”  This is taken from https://docs.microsoft.com/en-us/office365/admin/misc/password-policy-recommendations?view=o365-worldwide

I disagree with both of these policies and STRONGLY disagree with the policy from Microsoft.  I will explain my reasoning and hopefully will convince those of you with an 8-character password policy to change to something that is stronger.

When I am working on a pentest, one of the first things I do is see if there is a place that I can password spray.  These portals are often email, but sometimes they are custom login portals, VPN portals, or another login portal that employees use.  If the password policy is 8-character minimums, I will usually get in. Given a large enough field of users (found through recon), there is almost always at least one user who has a password of Fall2019, Summer19!, or Company123.  It used to be funny when that happened, but it happens so often that now it is just sad.

You might be saying to yourself, “All of my external portals use two-factor authentication, so I am good.”  Well, the two-factor authentication (2FA) is only as good as its implementation. One of my co-workers was able to get into a 2FA protected email account because one of the 2FA methods went to a Skype phone number.  Sounds secure, except the Skype account used only single factor. She logged in to Skype as the victim, sent the 2FA request to the Skype account, and then logged in to email.

I am in no means saying that we shouldn’t use 2FA because it can be bypassed.  2FA, if employed correctly, thwarts many attacks. I am only saying that we shouldn’t be ignoring the first method of protection – passwords.  If your first authentication method is difficult to bypass, many attackers won’t even be able to get to the second method of authentication.

So what should you make your password policy? The easy answer is at least 15 characters.  Why that length? We will be having a webcast on this very topic this week and you can register below. There will also be a follow-up blog with more explanation.

Webcast:

Register for our next webcast — Passwords: You Are the Weakest Link — on Dec 5, 2019, 1:00 PM EST at: https://attendee.gotowebinar.com/register/4720742581883580684



Ready to learn more?

Level up your skills with affordable classes from Antisyphon!

Pay-What-You-Can Training

Available live/virtual and on-demand