惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
A
About on SuperTechFans
G
Google Developers Blog
B
Blog RSS Feed
F
Fortinet All Blogs
WordPress大学
WordPress大学
Recent Announcements
Recent Announcements
Hugging Face - Blog
Hugging Face - Blog
Y
Y Combinator Blog
MongoDB | Blog
MongoDB | Blog
小众软件
小众软件
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
T
The Blog of Author Tim Ferriss
Jina AI
Jina AI
IT之家
IT之家
P
Proofpoint News Feed
美团技术团队
量子位
Microsoft Azure Blog
Microsoft Azure Blog
Engineering at Meta
Engineering at Meta
B
Blog
有赞技术团队
有赞技术团队
U
Unit 42

Black Hills Information Security, Inc.

Bad Habits: An ANTISOC Operation Same Problem, Different Angles: When Red Team and Blue Team Actually Talk to Each Other How to Identify and Exploit New Vulnerabilities Swapper – A Pure Regex Match/Replace Burp Extension A Practical Guide to BloodHound Data Collection Network Engineering Basics Signed, Trusted, and Abused: Proxy Execution via WebView2 Getting Started In Pentesting – Advice From The BHIS Pentest Lead Cloud Security: Tips and Resources for Securing the Cloud Lessons From A Chatbot Incident How to Lead Effective Tabletops Understanding GRC: How to Navigate Risks and Compliance Standards The “P” in PAM is for Persistence: Linux Persistence Technique Malware Analysis: How to Analyze and Understand Malware OSINT: How to Find, Use, and Control Open-Source Intelligence What to Do with Your First Home Lab When the SOC Goes to Deadwood: A Night to Remember Social Engineering and Microsoft SSPR: The Road to Pwnage is Paved with Good Intentions Common Cyber Threats Finding the Right Penetration Testing Company Deceptive-Auditing: An Active Directory Honeypots Tool The Curious Case of the Comburglar How to Set Smart Goals (That Actually Work For You) Inside the BHIS SOC: A Conversation with Hayden Covington Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation Why You Got Hacked – 2025 Super Edition Abusing Delegation with Impacket (Part 2): Constrained Delegation Abusing Delegation with Impacket (Part 1): Unconstrained Delegation GoSpoof – Turning Attacks into Intel Model Context Protocol (MCP)
Passwords: Our First Line of Defense
BHIS · 2019-12-04 · via Black Hills Information Security, Inc.

, , , , , ,

Darin Roberts //

“Why do you recommend a 15-character password policy when (name your favorite policy here) recommends only 8-character minimum passwords?” I have had this question posed to me a couple of times in the very recent past.  

There were 2 separate policies that were shown to me when asking these questions. First was the NIST policy.  From the NIST 800-63 guidelines, it says that “memorized secrets [are] to be at least 8 characters in length.”  Memorized secrets are defined to include passwords. The NIST guidelines were recently updated, but the password minimum length remains at 8 characters. Taken from https://blog.didierstevens.com/2017/02/28/password-history-analysis/.

The other policy was the policy for Microsoft Office 365.  This policy states that one recommendation “for keeping your organization as secure as possible” is to “maintain an 8-character minimum length requirement (longer isn’t necessarily better).”  This is taken from https://docs.microsoft.com/en-us/office365/admin/misc/password-policy-recommendations?view=o365-worldwide

I disagree with both of these policies and STRONGLY disagree with the policy from Microsoft.  I will explain my reasoning and hopefully will convince those of you with an 8-character password policy to change to something that is stronger.

When I am working on a pentest, one of the first things I do is see if there is a place that I can password spray.  These portals are often email, but sometimes they are custom login portals, VPN portals, or another login portal that employees use.  If the password policy is 8-character minimums, I will usually get in. Given a large enough field of users (found through recon), there is almost always at least one user who has a password of Fall2019, Summer19!, or Company123.  It used to be funny when that happened, but it happens so often that now it is just sad.

You might be saying to yourself, “All of my external portals use two-factor authentication, so I am good.”  Well, the two-factor authentication (2FA) is only as good as its implementation. One of my co-workers was able to get into a 2FA protected email account because one of the 2FA methods went to a Skype phone number.  Sounds secure, except the Skype account used only single factor. She logged in to Skype as the victim, sent the 2FA request to the Skype account, and then logged in to email.

I am in no means saying that we shouldn’t use 2FA because it can be bypassed.  2FA, if employed correctly, thwarts many attacks. I am only saying that we shouldn’t be ignoring the first method of protection – passwords.  If your first authentication method is difficult to bypass, many attackers won’t even be able to get to the second method of authentication.

So what should you make your password policy? The easy answer is at least 15 characters.  Why that length? We will be having a webcast on this very topic this week and you can register below. There will also be a follow-up blog with more explanation.

Webcast:

Register for our next webcast — Passwords: You Are the Weakest Link — on Dec 5, 2019, 1:00 PM EST at: https://attendee.gotowebinar.com/register/4720742581883580684



Ready to learn more?

Level up your skills with affordable classes from Antisyphon!

Pay-What-You-Can Training

Available live/virtual and on-demand