Please don't change your passwords!

Sorry, just couldn't resist on commenting on this article. I don't know how this guy/researcher comes up with these numbers and conclusions. Maybe he can blame it on sleeping while taking statistics classes, or his mother dropping him head first on the kitchen floor in the early days? I will not fight him about the numbers presented, they are I'm sure as accurate as they can be. But I must strongly disagree with the conclusions.
Of course you need to change your password frequently, or rather infrequently, but at least once every 90 days (my recommendation is every 30 days). Cormac Herley, the top Microsoft researcher who wrote the report, makes the comparison of losing your keys to your apartment for instance. Would you not notice that as soon as you try to get into your household, at the latest? Would you then change the locks? Probably if you had your name and address tag attached to your keys. Or it just might happen that your household was raided already. So when it comes to the assumption that the thief will not wait until you changed locks is certainly fair. But since your password travels with your username, you would probably change your password as soon as you found out that it was on the loose.
There are several twisted assumptions in his conclusions and makes me think of Freakonomics: A Rogue Economist Explores the Hidden Side of Everything (P.S.) and how statistics are both fun and dangerous.
Please do change your password now!

Comments

Popular posts from this blog

Overhead lines

R.I.P. Google Reader

Sweden 2 Australia