XCLUB-COOL STUFF AROUND YOU

 找回密码
 Register
查看: 59|回复: 6
打印 上一主题 下一主题

Microsoft Confirms Change To Windows 10 Passwords That Nobody Saw Coming

[复制链接]

3005

主题

5万

帖子

5万

积分

Super CP

Crazy TechnologyTech Fans2020Eid PartyHot PartyPOP OUTChocolate Day MedalTeddy Day MedalACTIVE STARphotographerssign star1sign star2sign star3post star1post star2post star3sign star4post star4X'Club badge exclusive for Indiapost star5sign star5

跳转到指定楼层
#1
发表于 2019-04-27 22:09:02 来自手机 | 只看该作者 |只看大图 回帖奖励 |倒序浏览 |阅读模式
[br] [br]Ask a bunch of security professionals what makes a secure password and you’ll get a bunch of different answers. Some will argue that it’s all about length, others that randomness and complexity are king while everyone will agree that password reuse is never acceptable. Some will still argue that giving passwords an expiry date, after which they must be changed, is an essential part of the business security policy picture. It would appear that, with the arrival of the Windows 10 May update, Microsoft is finally no longer going to be amongst that latter group. According to Aaron Margosis, a principal consultant with Microsoft, Windows 10 will no longer recommend “ancient and obsolete” periodic password expiration in the security baseline settings starting with the May update. While being most welcome, it has to be said nobody I have spoken to in the information security business saw that coming. Not least as the arguments for password expiration have been comprehensively dismantled for some years now yet Microsoft has not shown any inclination to jump from this particular sinking security ship.[br][br]The security baseline configuration has been part of the Windows staple diet for organizations wanting secure operating system settings out of the box for many years. It is actually a whole set of system policies that make good sense as a starting point for secure postures for many and as the default positioning for some. Things become problematic for organizations when they undergo an audit which uses the Microsoft security baseline and penalizes them for non-compliance if they have something other than the current 60 day Windows password expiration default maximum. Yet, as Margosis writes “recent scientific research calls into question the value of many long-standing password-security practices such as password expiration policies, and points instead to better alternatives such as enforcing banned-password lists and multi-factor authentication.”[br][br]The United States National Institute for Standards and Technology (NIST) has been recommending password expiration is dropped from security policy since 2016. Now it seems that Microsoft has finally caught up and will be dropping the requirement starting from Windows 10 (1903) and Windows Server (1903) onward. This makes perfect sense to me as someone who has been following information security trends for the best part of three decades. Things have changed over those years, not least the technology that now enables threat actors to crack simplistic passwords in the blink of an eye. Forcing users to change passwords over relatively short timeframes inevitably leads to those users choosing the simplest, and therefore most memorable, passwords possible. Stand up everyone who has never seen incremental numbering of short passwords in a corporate environment. I’m guessing everyone is still sitting down.[br][br]The days of simplistic passwords changed often are long gone, replaced by longer and more complex ones which don’t expire but rather are reinforced with those banned password lists and multifactor authentication for example. “While we recommend these alternatives, they cannot be expressed or enforced with our recommended security configuration baselines,” Margosis says “which are built on Windows’ built-in Group Policy settings and cannot include customer-specific values.” What Microsoft isn’t doing is changing baseline requirements for minimum password length, history, or complexity. It also isn’t stopping organizations from configuring password expiration if they must, for regulatory compliance reasons for example. “The password-expiration security option is still in Windows and will remain there,” Margosis says, adding “by removing it from our baseline rather than recommending a particular value or no expiration, organizations can choose whatever best suits their perceived needs without contradicting our guidance.”[br][br][br]#Infinix_India.....
回复

使用道具 举报

5736

主题

2万

帖子

3万

积分

Jade Diamond LV36

ACTIVE STAR2019post star1post star2sign star1sign star2sign star3post star3post star4post star5sign star4X'Club badge exclusive for India

#2
发表于 2019-04-27 22:11:38 来自手机 | 只看该作者
thanks for sharing
回复

使用道具 举报

1851

主题

1万

帖子

1万

积分

Content Partner

Rank: 8Rank: 8

Tech Fans2020COPYWRITERsign star1sign star2sign star3post star1post star2post star3sign star4X'Club badge exclusive for Indiapost star4

#3
发表于 2019-04-27 22:30:39 来自手机 | 只看该作者
good information dear Raju
回复

使用道具 举报

5051

主题

3万

帖子

3万

积分

Jade Diamond LV37

Tech Fans2020Happy children's dayEid PartyACTIVE STARXClub Best Look20MPrimary beta testerXCLUB TOP FAN 2019post star1post star2post star3post star4post star5sign star1sign star2sign star3sign star4X'Club badge exclusive for Indiasign star5

#4
发表于 2019-04-28 01:39:44 来自手机 | 只看该作者
Nice information....
回复

使用道具 举报

1万

主题

8万

帖子

9万

积分

Sapphire Diamond LV48

Crazy TechnologyDaily Check-inTech Fans2020PL KINGHappy children's dayEid PartyHot PartyDiamondHappy Easter Medal.pngGood Wallpaper DesignerChocolate Day MedalHug Day MedalKiss Day MedalPromise Day MedalPropose Day MedalTeddy Day Medalsingel medalACTIVE STAR2020 Wish Medal20M4.0xclub2019post star1post star2post star3sign star1sign star2sign star3sign star4post star4post star5X'Club badge exclusive for Indiasign star5

5#
发表于 2019-04-28 01:45:54 来自手机 | 只看该作者
Good share
回复

使用道具 举报

3005

主题

5万

帖子

5万

积分

Super CP

Crazy TechnologyTech Fans2020Eid PartyHot PartyPOP OUTChocolate Day MedalTeddy Day MedalACTIVE STARphotographerssign star1sign star2sign star3post star1post star2post star3sign star4post star4X'Club badge exclusive for Indiapost star5sign star5

6#
 楼主| 发表于 2019-04-28 10:14:36 来自手机 | 只看该作者
Thanks dear{:16_1:}{:16_21:}{:16_24:}
回复

使用道具 举报

2万

主题

18万

帖子

20万

积分

Super CP

couple medalStay HomeHappy Mother's DaySmileHappy children's dayEid PartyBest ReviewsX'Club badge exclusive for NigeriaXclub Kolpost star1sign star1post star2sign star2PL KINGTech Fans2020Weekly Tech Star2020Daily Check-inCrazy Technology

7#
发表于 2019-05-01 14:26:32 来自手机 | 只看该作者
Nice share brother
回复

使用道具 举报

高级模式
B Color Link Quote Code Smilies |上传

本版积分规则

Infinix Official Website|Infinix official mall|infinix Note 4|XCLUB-COOL STUFF AROUND YOU

GMT+8, 2025-02-26 03:43 , Processed in 0.036865 second(s), 23 queries .

Powered by Discuz! X3.4

© 2001-2017 Comsenz Inc.

快速回复 返回顶部 返回列表