Community Manager at Infosec!
Who we are | What we do
Microsoft to remove password expiration policy in Windows 10 1903

So Microsoft will be removing the password expiration policy in the 1903 May update, opting instead to simply urge users to use "more modern and better password-security practices such as multi-factor authentication, detection of password-guessing attacks, detection of anomalous log on attempts, and the enforcement of banned passwords lists."
https://www.bleepingcomputer.com/news/microsoft/windows-10-1903-gets-rid-of-password-expiration-policies/
What do you think? Is this maybe unnecessary, or is a change like this needed to force the industry in the right direction? I'm on the fence about it, but I think it's ultimately the right move. Like they say in the article, password expiration is becoming more and more obsolete, and just causes people to use similar passwords in order to remember them.
https://www.bleepingcomputer.com/news/microsoft/windows-10-1903-gets-rid-of-password-expiration-policies/
What do you think? Is this maybe unnecessary, or is a change like this needed to force the industry in the right direction? I'm on the fence about it, but I think it's ultimately the right move. Like they say in the article, password expiration is becoming more and more obsolete, and just causes people to use similar passwords in order to remember them.
Comments
On one hand, some people use the same password for all their logins. Higher risk of compromise.
- MFA
- Checks against and blacklisting know "bad" passwords (too easy + exposed in previous breaches)
- Some sort of password strength meter (although it could be subjective depending on implementation)
- Rate limiting (captchas, et. al.)
- Allowing paste from password managers
- Forcing pwd change if there's high confidence of compromise
- etc.
In reality, we'll be back at square zero where mature companies will do the right thing and many others will not care. I just saw the example the other day of a bank prohibiting copy/paste of pwd in their web apps because "it's the most secure thing to do".
Who we are | What we do
Security Engineer/Analyst/Geek, Red & Blue Teams
OSCP, GCFA, GWAPT, CISSP, OSWP, AWS SA-A, AWS Security, Sec+, Linux+, CCNA Cyber Ops, CCSK
2021 goals: maybe AWAE or SLAE, bunch o' courses and red team labs?