Path: csiph.com!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: Huge Newsgroups: comp.misc Subject: Re: [Link Posting] Password expiration is dead, long live your passwords Date: 11 Jun 2019 18:21:08 GMT Organization: Piglet's Pickles & Preserves Lines: 21 Message-ID: References: Reply-To: usenet@huge.org.uk X-Trace: individual.net Ifol0dz4aM75qb+bAPbvAw7V6jo/oFMUDBwbHXRMk97gKAVt7e Cancel-Lock: sha1:eoXr16ehvfGOwt/gmNmYNdatgcM= X-No-Archive: Yes X-Clacks-Overhead: GNU Terry Pratchett User-Agent: slrn/1.0.3 (Linux) Xref: csiph.com comp.misc:18188 On 2019-06-11, Kerry Imming wrote: > On 6/11/2019 1:42 AM, Sylvia Else wrote: >> Why did this take so long? Why did so many people think it was a good >> idea to force password changes? > > My thought was that it dated back to logging in to a command line (as > described in Clifford Stoll's book, "The Cuckoo's Egg") vs. a web page. > A hacker then had access to explore the system as long as no changes > were made that would cause them to be detected. Changing the password > would limit this exploration time. On a Unix system, once you're logged on, changing the logon password makes no difference whatsoever (unless the user tries to use a tool which re-reads the password, e.g. sudo). Not sure your web analogy is very good, either. -- Today is Boomtime, the 16th day of Confusion in the YOLD 3185 Rising above bedlam