RE: Password changes more than once per day

From: Joey Peloquin (jpelo1_at_jcpenney.com)
Date: 02/11/04

  • Next message: Nagy Gergely: "RE: Security presentation"
    Date: Tue, 10 Feb 2004 18:08:41 -0600
    To: "'Bob Kelley'" <bob_kelley_jr@yahoo.com>, security-basics@securityfocus.com
    
    
    

    Bob,

    It actually works in tandem with the 'Enforce Password History' setting,
    preventing users from resetting their password several times in a short
    period. For example, if Enforce Password History is set to remember 10
    passwords, and the user's password has no minimum age, they could change
    their password 10 times, effectively allowing them to use the same password
    forever.

    Maybe it's time to remind the user *why* we have password policies in the
    first place? Sounds like they'd be happy to circumvent the policy
    altogether.

    Joey Peloquin

    >>-----Original Message-----
    >>From: Bob Kelley [mailto:bob_kelley_jr@yahoo.com]
    >>Sent: Tuesday, February 10, 2004 3:32 PM
    >>To: security-basics@securityfocus.com
    >>Subject: Password changes more than once per day
    >>
    >>
    >>
    >>
    >>Can someone please explain the security implications of
    >>allowing a user to change their password more than one time
    >>per day without involving an account administrator? What's the risk ?
    >>
    >>
    >>
    >>I specified the security requirement of not allowing a user
    >>to change their password more than once per day for an
    >>outsourcing project and I am being asked why. I could not
    >>remember my reasoning other than it's a requirement for
    >>microsoft security policies to ensure password history is enforced.
    [...]

    
    

    The information transmitted is intended only for the person or entity to
    which it is addressed and may contain confidential and/or privileged
    material. If the reader of this message is not the intended recipient,
    you are hereby notified that your access is unauthorized, and any review,
    dissemination, distribution or copying of this message including any
    attachments is strictly prohibited. If you are not the intended
    recipient, please contact the sender and delete the material from any
    computer.

    
    

    ---------------------------------------------------------------------------
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.

    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.

    Download 30-day evaluation at:
    http://www.astaro.com/php/contact/securityfocus.php
    ----------------------------------------------------------------------------


  • Next message: Nagy Gergely: "RE: Security presentation"

    Relevant Pages

    • RE: Password changes more than once per day
      ... bypass the password history. ... Astaro Security Linux -- firewall with Spam/Virus Protection ... Wireless security. ...
      (Security-Basics)
    • Oracle 11g (11.1.0.6) Password Policy and Compliance
      ... In Oracle 11g, if a security administrator has enabled 11g passwords exclusively then tracking password history is broken. ... The views expressed in this email do not necessarily reflect NGS policy. ...
      (Bugtraq)
    • [Full-disclosure] Oracle 11g (11.1.0.6) Password Policy and Compliance
      ... Many security standards require the tracking of users' password history to ... This was addressed by Oracle ... The views expressed in this email do not necessarily reflect NGS policy. ...
      (Full-Disclosure)
    • Re: ADSI, password change, password history
      ... the oUser.ChangePassword enforces the password history. ... >> The oUser.SetPassword does NOT enforce password history ... (perhaps even have the helpdesk person do this so the user never even knows ... Then don't give them a copy of the assigned password for them to take away ...
      (microsoft.public.windows.server.scripting)
    • Re: ADSI, password change, password history
      ... the oUser.ChangePassword enforces the password history. ... >> The oUser.SetPassword does NOT enforce password history ... (perhaps even have the helpdesk person do this so the user never even knows ... Then don't give them a copy of the assigned password for them to take away ...
      (microsoft.public.win2000.security)