Home
Calendar
Certifications
Columns
Features
Forum
Resources
Vitals
Latest Additions
April 2013 Free Giveaway Sponsor - eLearnSecurity
Human Intelligence to Navigate the Security Data Deluge
February 2013 Free Giveaway Winner of SANS CyberCon Training
Interview: Bugcrowd Founders on Herding Ninjas for Crowdsourced Bug Bounties
Network Forensics: The Tree in the Forest
March 2013 Free Giveaway Sponsor - Mile2
Book Review: Violent Python
February 2013 Free Giveaway Sponsor - SANS
Holiday 2012 Free Giveaway Winner of Metasploit Pro by Rapid7
Course Review: SANS FOR408 Computer Forensic Investigations – Windows In-Depth
The Security Consulting Sugar High
Tutorial: Fun with SMB on the Command Line
Interview: Ilia Kolochenko, CEO of High-Tech Bridge
October 2012 Free Giveaway Winner of LearningGate Training
The Broken: Assessing Corporate Security in 2012 to Make a Better 2013
EH-Net Login
Welcome Guest.
Username:
Password:
Remember me
Lost Password?
No account yet?
Register
Who's Online
We have 29 guests online
You are here:
Home
Ethical Hacking Discussions and Related Certifications
Other
Best Practices for Password Policy
EH-Net
May 23, 2013, 09:34:37 PM
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
News
: Go back to The Ethical Hacker Network Online Magazine
Home Page
Home
Help
Calendar
Login
Register
EH-Net
>
Ethical Hacking Discussions and Related Certifications
>
Other
(Moderator:
don
) >
Best Practices for Password Policy
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: Best Practices for Password Policy (Read 14164 times)
0 Members and 1 Guest are viewing this topic.
awhitehatter
Newbie
Offline
Posts: 19
Best Practices for Password Policy
«
on:
February 28, 2011, 05:34:54 PM »
Hi All,
Wasn't sure if this belonged in the regulatory and compliance section as it is more geared to best practices.
I'm looking for information to support our current password policy. Specifically best practices on local administrator accounts, service accounts, etc. Practical stuff on expiration dates, the sharing of, archiving old expired passwords or anything along those lines.
Does anyone have suggestions or links they can recommend? I can provide more info if you need it.
thanks for reading,
Logged
cd1zz
Hero Member
Offline
Posts: 561
Re: Best Practices for Password Policy
«
Reply #1 on:
February 28, 2011, 06:45:34 PM »
Do you fall under any compliance or government regulations?
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
Lubinski
Newbie
Offline
Posts: 26
Re: Best Practices for Password Policy
«
Reply #2 on:
February 28, 2011, 06:54:22 PM »
Here is a Sans link to their policies page, some good stuff in there regarding policies.
http://www.sans.org/security-resources/policies/
Regarding best practices here is a link to the NIST National Checklist Program which has some "checklist" style guides on recommended configuration of different OS's.
http://web.nvd.nist.gov/view/ncp/repository
Password policies are great examples of security vs. usability. Just remember a strong password policy might result in increased help desk calls, and general frustration of the administrator(s). The best password policy is one that you stick to and not make "exceptions" for the boss's son.
Logged
awhitehatter
Newbie
Offline
Posts: 19
Re: Best Practices for Password Policy
«
Reply #3 on:
February 28, 2011, 09:46:24 PM »
Quote from: cd1zz on February 28, 2011, 06:45:34 PM
Do you fall under any compliance or government regulations?
CDIZ, we have remote sites that do fall under HIPAA, some state cyber security laws and sometimes NIST SP 800-53. We don't have a security framework for our overall company at the time being (it's one of our goals).
Quote from: Lubinski on February 28, 2011, 06:54:22 PM
Here is a Sans link to their policies page, some good stuff in there regarding policies.
http://www.sans.org/security-resources/policies/
Regarding best practices here is a link to the NIST National Checklist Program which has some "checklist" style guides on recommended configuration of different OS's.
http://web.nvd.nist.gov/view/ncp/repository
Password policies are great examples of security vs. usability. Just remember a strong password policy might result in increased help desk calls, and general frustration of the administrator(s). The best password policy is one that you stick to and not make "exceptions" for the boss's son.
Thanks for the links Lubinski, I'll check them out.
Logged
timmedin
Sr. Member
Offline
Posts: 469
Re: Best Practices for Password Policy
«
Reply #4 on:
March 01, 2011, 08:33:29 PM »
Microsoft did a great study on passwords, rotation, and complexity.
http://research.microsoft.com/apps/pubs/?id=74164
In short, the more often a password was rotated, the less complexity users employed. My push has been to require much more complex
passwords
passphrases and rotate them yearly (not every 90 days).
As for service accounts and other non-user accounts. Always keep them at least 15 characters. That way it prevents the cryptographic weakness in Windows Lan Manager from even being an issue.
Logged
twitter.com/timmedin |
http://blog.securitywhole.com
cd1zz
Hero Member
Offline
Posts: 561
Re: Best Practices for Password Policy
«
Reply #5 on:
March 01, 2011, 09:30:28 PM »
timmedin is right on. Passphrases are the way to go, especially if you can avoid dictionary words. However you dont want passwords so complex that people are leaving sticky notes all over the place. But this is where some education or help to your users will come in nicely.
Logged
OSCE | OSCP | GXPN | OSWP | CISSP
http://www.pwnag3.com
http://www.networkadminsecrets.com
jsm725
Newbie
Offline
Posts: 36
Re: Best Practices for Password Policy
«
Reply #6 on:
March 02, 2011, 04:24:34 PM »
I am a big fan of passphrases. Easy to remember and don't need to be changed as often. I like to pitch it to clients as a cost savings for their help desk with the decrease in passwords resets needed.
My only caution would be that changing once a year might leave you susceptible to other forms of attack that frequently changing your passwords help defend against (i.e. social engineering).
Depending on the regulatory environment, some of this stuff may be decided for you though.
Logged
CISSP, PCI-QSA, OSWP
3xban
Hero Member
Offline
Posts: 608
Re: Best Practices for Password Policy
«
Reply #7 on:
May 07, 2011, 03:47:45 PM »
I'm another fan of the passphrase. Definitely the way to go. As for the local admin and service accounts, since you won't be changing those as often as the user accounts, use very long passphrases, sentences from books or even history facts tent to work best. But make them long. I am currently in the process of having my organization move out of the password arena and into passphrases, sadly I have an ISO that is not very bright and doesn't get some of these concepts. Yes I don't know how he got the job either. Anyway good luck and if you have some stubborn users, make sure to reiterate the ease of remembering them. Hell for the ones that like to "secure" them under their keyboard, you can even mention that they can keep the phrase on a sticky note on their monitor and no one might think anything of it "Meeting on Friday!"
Logged
Certs: GCWN
(@)Dewser
R3B005t
Newbie
Offline
Posts: 43
Re: Best Practices for Password Policy
«
Reply #8 on:
May 09, 2011, 08:14:04 AM »
Ahh the age old problem that every IT department faces, passwords. The complexity requirements at my current place of employment are I'm sure the bane of the helpdesk. I'd love to go to passphrase's however I'm sure we wouldn't be able to due to the strict gov regs that companies in my industry face. We are actually looking at beefing up secuirty even further by utilizing CAC card's in addition to our normal password complexity requirments. One thing I'm currently working on is getting the ISO to make all the Domain Admins use two seperate accounts. One with User level rights for day to day stuff and the other a unique domain admin accout to use for any work that requires elevated permissions. I myself have been working this way for about 6 mo. at first it was difficult but you quickly adapt to creating short cuts with runas in the target path. I've taken to documenting cases where users have their passwords written down. God one of our users who handles finances had a file called Passwords.xls out on a freaking network share that was accessable to everyone.
Logged
WCNA
Full Member
Offline
Posts: 187
Re: Best Practices for Password Policy
«
Reply #9 on:
May 09, 2011, 10:00:05 AM »
I'll second the opinion that passphrases are the way to go AND I would add... use numbers and special characters in your pass phrase as well.
Also, you have to be aware of password reuse. (Wasn't it H.D. Moore that got caught in that recently?.... and HB Gary too)
I suggest to users to use different phrases for different places such as "Ih82comein2work" (I hate to come into work) for the workplace and "BF!onmywayhomeagain" (which stands for the song Blind Faith- On my way home again), obviously for the home computer password
Logged
ISC2 Associate, WCNA, CWNA, OSCP, Network+
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
EH-Net
-----------------------------
=> Calendar Of Events
===> ChicagoCon 2007
===> ChicagoCon 2008s
===> ChicagoCon 2008f
===> ChicagoCon 2009s
=> Ethical Hacktivism
=> News Items and General Discussion About EH-Net
===> Greetings
=> Special Events
-----------------------------
Ethical Hacking Discussions and Related Certifications
-----------------------------
=> General Certification
===> Networking
===> OS
===> Security
=> Compliance, Regulations & Standards
=> Control Systems
=> Cyber Warfare
=> Forensics
===> CCE / MCCE - (Master) Certified Computer Examiner
===> CHFI - Computer Hacking Forensic Investigator
===> EnCE - EnCase® Certified Examiner
===> GCFA - GIAC Certified Forensics Analyst
=> Hardware
=> Incident Response
===> CSIH - Computer Security Incident Handler
===> GCIH - GIAC Certified Incident Handler
=> Malware
===> Advisories
=> Mobile
=> Network Pen Testing
===> CEH - Certified Ethical Hacker
===> CPTC - Certified Penetration Testing Consultant
===> CPTE - Certified Penetration Testing Engineer
===> CSTA - Certified Security Testing Associate
===> eCPPT - eLearnSecurity Certified Professional Penetration Tester
===> ECSA - EC-Council Certified Security Analyst
===> GPEN - GIAC Certified Penetration Tester
===> OSCP - Offensive Security Certified Professional
=> Physical Security
=> Programming
=> Social Engineering
=> Web Applications
=> Wireless
===> CWNP Certs
===> GAWN - GIAC Assessing Wireless Networks
===> OSWP - Offensive Security Wireless Professional
=> Other
-----------------------------
Columns
-----------------------------
=> Editor-In-Chief
=> Andress
=> Gates
=> Haddix
=> Hadnagy
=> Heffner
=> Hoffman
=> Linn
=> RichM
=> Murray
=> J. Peltier
=> Weidman
=> Wilson
-----------------------------
Features
-----------------------------
=> /root
=> Book Reviews
=> Opinions
=> Skillz
===> Examples
===> May 06 - Star Hacks, Episode V: The Empire Hacks Back
===> July 06 - Hack Bill!
===> Sept 06 - Netcat in the Hat
===> Nov 06 - Hitch-Hackers Guide to the Galaxy
===> Dec 06 - A Christmas (Hacking) Story
===> Feb 07 - Charlottes Web Site
===> April 07 - Microsoft Office Space
===> June 07 - Serenity Hack
===> Oct 07 - Worst. Ethical. Hacker. Challenge. Ever.
===> Dec 07 - Frosty the Snow Crash
===> March 2008 - It Happened One Friday
===> Oct 2008 - Scooby Doo and the Crypto Caper
===> Dec 08 - Santa Claus Is Hacking to Town
===> Feb 2009 - Brady Bunch Boondoggle
===> July 2009 - Prison Break
===> October 2009 - SSHliders
===> December 2009 - Miracle on Thirty-Hack Street
===> December 2010 - The Nightmare Before Charlie Browns Christmas
-----------------------------
Resources
-----------------------------
=> Career Central
===> Looking For Work
===> Looking To Hire
=> Links to cool sites.
=> Mass Media
=> News from the Outside World
=> Tools
=> Tutorials
===> Tutorial Requests
Loading...
Exclusive Deal
SANSFIRE 2013
June 15 - 22
5% Off
w/ Code
:
EHN_5
SANS Deals 4 EH-Netters
5% OFF
Any
SANS Course
in Any Format!
Coupon Code:
EHN_5
Including
SANS Rocky Mountain 2013
&
SANS Boston 2013
Polls
Compared to this year, 2013 will be:
Great!
Better.
About the same.
Little worse.
FUBAR!
Recent Forum Topics
GCIH - GIAC Certified Incident Handler
: Passed my GCIH
(6) by
azmatt
Greetings
: Hi from the UK
(4) by
MrTuxracer
GCIH - GIAC Certified Incident Handler
: GCIH Free Practice test attempt
(0) by
prats84
News Items and General Discussion About EH-Net
: Change is Coming to EH-Net!!
(27) by
don
Network Pen Testing
: AIX Vulnerability Assessments
(2) by
ras76
Tutorials
: Need guidance
(9) by
hanyhasan
EH-Net News Feeds
Latest Additions
Privacy Notice
for TDCC & All Properties
Free Business and Tech Magazines and eBooks
© 2013 The Ethical Hacker Network
Joomla!
is Free Software released under the GNU/GPL License.