Skip to main content

FTC flouts conventional wisdom, says changing passwords often can do harm

Hacker
hamburg_berlin/Shutterstock
Conventional wisdom takes another hit. For more than 30 years, one of the most common computer security tips has been to change your passwords often. Make them complex, don’t use the same ones over and over, don’t write them on sticky notes pasted to your monitor, and change them regularly. The FTC wants you to forget that last piece of advice, according to Ars Technica.

Speaking at PasswordsCon 2016 last week, Federal Trade Commission Chief Technologist Lorrie Cranor spoke about her own surprise when she left Carnegie Mellon University to work at the FTC. Cranor discovered that not only did the agency tell employees to encourage friends and family to change passwords often, she herself now had six new government passwords that she was required to change every 60 days.

Cranor told FTC information and security officers that changing passwords often can lead to weaker security because users make predictable changes hackers can detect with algorithms. Asked for proof of this unexpected assertion, Cranor got it.

In 2010, researchers from the University of North Carolina at Chapel Hill studied 10,000 expired university accounts for which they were able to trace password history. The account holders had been required to change passwords every three months. Most commonly, the users made only minimal changes to their passwords, using detectable patterns. For example, a user might progressively capitalize one letter in a password, advancing to the next letter with each change, for example, “Pumpkin77!,””pUmpkin77!,” and “puMpkin77!.” Another common pattern was to increase a digit when changing, such as “Pumpkin1!,” “Pumpkin2!,” and “Pumpkin3!.” The researchers developed algorithms that could crack accounts before lockout 17 percent of the time.

Additional studies from Canada’s Carleton University, the National Institute of Standards and Technology, and the U.K.’s CESG (Communications-Electronics Security Group) all showed that frequent and mandated password changes inconvenienced users to the point that the users created detectable passwords. In other words, conventional wisdom backfired.

Cranor reported that as a result of her research, the FTC is gradually changing internal procedures away from required password changes.

The advice to change passwords makes sense if all users create long, complex passwords with, for example, more special characters than letters or digits. Most people, however, take the easier route and use easy to remember passwords and change them when required in detectable patterns.

Editors' Recommendations

Bruce Brown
Digital Trends Contributing Editor Bruce Brown is a member of the Smart Homes and Commerce teams. Bruce uses smart devices…
Best gaming laptop deals: Alienware, Razer, Asus and more
An Alienware m16 gaming laptop in use on a desk, playing Baldur's Gate III.

Gaming can be a lot of fun, but if you're the sort of person who doesn't want to deal with a big gaming desktop, then going for a gaming laptop makes a lot of sense. Of course, you aren't going to get as much power under the hood as you would with a desktop, and it might cost a bit more, but you do get a lot of mobility and an included screen in the process. Either way, modern gaming laptops have become really great, and even the budget-oriented stuff can play some of the best PC games out there.

To that end, we've gone out and collected some of our favorite gaming laptop deals out there. On the other hand, if you don't want something that yells "gaming laptop," check out some of these other laptop deals that include more traditional-looking laptops with some gaming specs.
IdeaPad Gaming 3 gaming laptop -- $617, was $950

Read more
Best Antivirus Deals: Protect your PC or Mac from just $35
norton 360 deluxe with lifelock deal best buy december 2021 antivirus shutterstock stock image

If you just grabbed one of these desktop deals or laptop deals, then you may want to also consider arming yourself with one of the best antivirus programs on the market. That's especially true since the antiviruses that tend to come with these deals only last 30 days or so and don't even include the full suite of tools. So, if you want protection against everything from viruses to phishing scams, then be sure to check our favorite antivirus deals below.
NortonLifeLock 360 Deluxe -- $35, was $90

Norton products are a firm fixture amongst the best antivirus software for good reason. They're simple to use and typically cover all the devices you could need to protect. In the case of NortonLifeLock, you get so much more than just antivirus protection too. The software package covers up to five devices at once meaning it will happily work on your Windows, Mac, Android, and iOS systems all at once without a problem. That means all your devices will be regularly monitored for any nefarious files or any other potential issues relating to malware or similar. Real-time protection means there's nothing you need to do other than keep an eye out for any alerts from the service. It's great peace of mind but Norton LifeLock 360 Deluxe goes further than that.

Read more
Best Samsung monitor deals: 4K monitors, ultrawide, and more
Press image of the Samsung ViewFinity S9 studio monitor.

Samsung is probably one of the most well-known electronics companies, making everything from some of the best phones on the market to washers and driers, so it has a huge pedigree in the tech field. That pedigree also extends to monitors, as it also makes some of the best monitors and best gaming monitors on the market as well, so if you're looking to buy a new one, grabbing a Samsung on is a pretty smart choice. Of course, there's a huge selection of monitors to pick from, which is why we've gone out and selected some of our favorite Samsung monitor deals and compiled them for you below.

Also, if you're not quite sure what monitor to buy, check out our computer monitor buying guide to get a better sense of what you need. And, if you don't find it among Samsung monitors, you can always check some other great monitor deals as well.
Samsung 22-inch T350 Full HD monitor -- $100, was $120

Read more