WeLiveSecurity 2024年07月05日
How often should you change your passwords?
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

密码安全一直是人们关注的焦点,但关于多久更换一次密码却存在争议。传统观点认为定期更换密码可以提高安全,但最新研究表明,频繁更换密码可能并不能有效提升账号安全,反而可能降低安全性。本文将探讨密码更换的利弊,并给出最佳密码安全建议。

🤔 **频繁更换密码可能降低安全性:** 研究表明,频繁更换密码会导致用户选择更弱的密码,并倾向于使用与旧密码类似的密码,这反而会降低安全性。此外,频繁更换密码也更容易导致用户记录或忘记密码,反而增加了被攻击的风险。

💡 **何时需要更改密码:** 尽管频繁更换密码可能弊大于利,但以下情况则需要及时更改密码: * 密码泄露:如果你的密码在第三方数据泄露事件中被泄露,则需要立即更改密码。 * 密码过于简单:如果你的密码过于简单或容易被猜测,则需要更改为更强的密码。 * 密码在多个账号中重复使用:如果你的密码在多个账号中重复使用,则其中一个账号被攻击后,攻击者可能会使用“凭证填充”软件攻击其他账号。 * 设备被恶意软件感染:如果你的设备被恶意软件感染,则需要更改所有账号的密码。 * 密码被他人知晓:如果你将密码分享给他人,则需要立即更改密码。 * 从共享账户中移除用户:如果你从共享账户中移除用户,则需要更改密码。 * 在公共电脑上登录:如果你在公共电脑上登录账号,则需要更改密码。

🔐 **最佳密码安全建议:** * 使用强壮、独特且长密码:密码应包含大小写字母、数字和特殊符号,长度至少12位。 * 使用密码管理器:密码管理器可以帮助你存储和管理所有密码,并自动生成强壮的密码。 * 启用双重身份验证:双重身份验证可以为你的账号提供额外的安全保护。 * 定期进行密码安全审计:定期检查所有账号的密码,确保它们没有重复使用或过于简单。 * 不要在浏览器中保存密码:浏览器是攻击者的目标,他们可能会使用恶意软件窃取你保存的密码。

🔑 **未来趋势:** 随着密码密钥(passkey)技术的普及,密码时代或许将终结。目前,谷歌、苹果、微软等科技巨头都在积极推动密码密钥技术的应用。

🔓 **密码安全,重在预防:** 养成良好的密码安全习惯,可以有效降低账号被攻击的风险。

🌟 **密码安全:人人有责!**

Digital Security How often should you change your passwords? And is that actually the right question to ask? Here’s what else you should consider when it comes to keeping your accounts safe. 03 Apr 2024  •  , 5 min. read Much has been made over the past few years about the growing potential in passwordless authentication and passkeys. Thanks to the near-ubiquity of smartphone-based facial recognition, the ability to log into your favorite apps or other services by looking into your device (or another method of biometric authentication, for that matter) is now a refreshingly simple and secure reality for many. But it’s still not the norm, especially across the desktop world, with many of us still relying on good ol’ passwords.This is where the challenge lies – because passwords remain a major target for fraudsters and other threat actors. So how often should we change these credentials in order to keep them secure? Answering this question may be trickier than you think.Why password changes may not make senseUntil not too long ago, it was recommended to regularly rotate passwords in order to mitigate the risk of covert theft or cracking by cybercriminals. The received wisdom was anywhere between 30 and 90 days.However, the times they are a-changing and research suggests that frequent password changes, especially on a set schedule, may not necessarily improve account security. In other words, there isn’t a one-size-fits-all answer to when you should change your password(s). Also, many of us have too many online accounts to comfortably keep track of, let alone come up with (strong and unique) passwords for each of them every few months. Also, we now live in a world of password managers and two-factor authentication (2FA) almost everywhere.The former means it is easier to store and recall long, strong and unique passwords for every account. The latter adds a fairly seamless extra layer of security onto the password login process. Some password managers now have dark web monitoring built in to automatically flag when credentials may have been breached and circulated on underground sites.At any rate, there are some compelling reasons why security experts and globally respected authorities, such as the US National Institute of Standards and Technology (NIST) and the UK’s National Cyber Security Centre (NCSC), do not recommend that people are forced to change their passwords every few months unless certain criteria have been met.The rationale is fairly simple:According to NIST: “Users tend to choose weaker memorized secrets when they know that they will have to change them in the near future”.“When those changes do occur, they often select a secret that is similar to their old memorized secret by applying a set of common transformations such as increasing a number in the password,” NIST continues.This practice provides a false sense of security because if a previous password has been compromised and you don’t replace it with a strong and unique one, the attackers may easily be able to crack it again.New passwords, especially if created every few months, are also more likely to be written down and/or forgotten, according to the NCSC.“It’s one of those counter-intuitive security scenarios; the more often users are forced to change passwords, the greater the overall vulnerability to attack. What appeared to be a perfectly sensible, long-established piece of advice doesn’t, it turns out, stand up to a rigorous, whole-system analysis,” the NCSC argues.“The NCSC now recommend organizations do not force regular password expiry. We believe this reduces the vulnerabilities associated with regularly expiring passwords while doing little to increase the risk of long-term password exploitation.”When to change your passwordHowever, there are several scenarios that necessitate a password change, especially for your most important accounts. These include:Your password has been caught in a third-party data breach. You will likely be informed about this by the provider themselves, or you may have signed up for such alerts on services such as Have I Been Pwned, or you might be notified by your password manager provider running automated checks on the dark web.Your password is weak and easy-to-guess or crack (i.e., it may have appeared on a list of most common passwords). Hackers can use tools to try common passwords across multiple accounts in the hope that one of them works – and more often than not, they succeed.You have been reusing the password across multiple accounts. If any one of these accounts is breached, threat actors could use automated “credential stuffing” software to open your account on other sites/apps.You have just learned, for example thanks to your new security software, that your device was compromised by malware.You have shared your password with another person.You have just removed people from a shared account (e.g., former housemates).You have logged in on a public computer (e.g., in a library) or on another person’s device/computer. Best practice password adviceConsider the following in order to minimize the chances of account takeover:Always use strong, long and unique passwords.Store the above in a password manager which will have a single master credential to access and can automatically recall all of your passwords to any site or app.Keep an eye on breached password alerts and take immediate action after receiving them.Switch on 2FA whenever it is available to provide an additional layer of security to your account.Consider enabling passkeys when offered for seamless secure access to your accounts using your phone.Consider regular password audits: review passwords for all of your accounts and ensure they are not duplicated or easy to guess. Change any that are weak or repeated, or ones that may contain personal information like birthdays or family pets.Don’t save your passwords in the browser, even if it seems like a good idea. That’s because browsers are a popular target for threat actors, who could use info-stealing malware to capture your passwords. It would also expose your saved passwords to anyone else using your device/computer.If you don’t use the random, strong passwords suggested by your password manager (or ESET’s password generator), consult this list of tips from the US Cybersecurity and Infrastructure Security Agency (CISA). It suggests using the longest password or passphrase permissible (8-64 characters) where possible, and including upper- and lower-case letters, numbers and special characters.In time, it is hoped that passkeys – with the support of Google, Apple, Microsoft and other major tech ecosystem players – will finally signal an end to the password era. But in the meantime, ensure your accounts are as secure as possible.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

密码安全 密码管理 密码密钥 网络安全 数据安全
相关文章