// Security NEWS // The Automatic Passwords Expiration in Windows 10 Is Soon Finished!

in #news5 years ago

In the latest recommendations published around the 1903rd future update of Windows 10, Microsoft announced the removal of the automatic passwords expiration for businesses.

windows-security-guide.jpg
Source

You may be familiar with the "fun" of having to change your Windows password regularly on your workstation. This era is about to be over. Microsoft has decided to skip this old security measure in the final draft of its Windows 10’s configuration document, future updates of its operating system that should be available in the future weeks coming.

In the new baseline, Microsoft is also considering dropping the long-standing requirement to disable the Guest account and the default Administrator account. Windows 10 disables the Guest account by default already, meaning that if it's enabled, it's probably for a good reason and shouldn't be picked up in an audit.

A measure to enhance security

The reasons given are that this "protection" is no longer one: these regular changes forces the users to remember not complex passwords that they evolve in a simple way - "toto123", "toto234", " toto345 ", etc.

What's more likely to lower security rather than reinforce it: it's better to create a long and complex password than a variable but simple passwords.

Periodic password expiration is a defence only against the probability that a password (or hash) will be stolen during its validity interval and will be used by an unauthorized entity. If a password is never stolen, there’s no need to expire it. And if you have evidence that a password has been stolen, you would presumably act immediately rather than wait for expiration to fix the problem.

Information that will delight workers who see their remote access to their post or access to their mail pro off during a vacation because it was precisely at that time that it was necessary to change ...

A proposition of Ars technical's reader saying: To make life miserable for the users again while increasing security enormously, I propose a new rule instead: passwords that appeared in a previous leak or breach cannot be used. For everybody. Globally. Rainbow tables, dictionary attacks, etc., all a thing of the past!

Do you have another proposition? Maybe more realistic :p

Source: Microsoft via Ars technical

Stay Informed, Stay Safe

DQmdpsoEfLe5nRg4Q1oKWHNjLdMnAucCYfRou1yF5Yiwrzs.png

DQmNuF3L71zzxAyJB7Lk37yBqjBRo2uafTAudFDLzsoRV5L.gif

Sort:  


@vijbzabyss, sorry to see you have less Steem Power.
Your level lowered and you are now a Red Fish!
Vote for @Steemitboard as a witness to get one more award and increased upvotes!

Coin Marketplace

STEEM 0.20
TRX 0.13
JST 0.030
BTC 66561.16
ETH 3492.16
USDT 1.00
SBD 2.63