Page 1 of 1

Common Sense About Passwords

Posted: Sat Oct 30, 2004 9:16 pm
by RuffRyders
[b]Common Sense About Passwords [/b]
[i]Think you know everything about passwords? Think they're boring? Wrong! Columnist Wayne Rash gives you the lowdown on sensible password management, and why it's easier than you think.[/i]

[size=1]By Wayne Rash [/size]

Passwords are a pain, but new thinking about passwords and some new tools make it possible to make passwords easier to manage and more effective.
Passwords are expensive for IT staff to manage. Security managers need to create and enforce policies to define the length and characteristics of user passwords and require users to make regular changes. Security managers must also change passwords when they're lost and give users access to systems when passwords are forgotten. All of this management is time-consuming and expensive for the help desk and other IT staff.

The first step in sensible password management is to decide how strong your passwords need to be. They should be as strong as necessary—but no stronger.

Really strong passwords, with random letter and number combinations and a mix of upper- and lower-case letters, are hard to guess, but they're also hard to remember, meaning you'll have to provide more user support, and users are more likely to write passwords down where attackers can see them.

Weak passwords are easy to remember, but also easy to compromise.

Moreover, you need to figure out how much exposure you have, how easy it is for an intruder to access your network long enough to try to crack your passwords. After all, the best password-guessing program in the world won't help an attacker who can't reach the login prompt.

Indeed, strong passwords are useless for most network attacks, because most attacks don't rely on passwords at all, said Dr. Peter Tippett, CTO of security consultants Cybertrust.

"They're an overblown concept," Tippett said.

About the only password-protection most people need is to keep their co-workers from reading their e-mail while they're at lunch.

The major security liability from passwords is that it's always possible to crack at least some of the passwords on a large network, given physical access and the right tools. Modern cracking programs can quickly guess 20 percent to 30 percent of the passwords on most networks.

"Modern cracking programs know the habits of humans," Tippett said.

The secret to passwords is not to depend on them too much, and instead to focus on keeping people away from your network in the first place, both through physical security and by using virtual private networks and other tools to secure the network itself, he said.

Security managers also need to figure out what they're trying to protect, and how much damage an intruder can do if the password is compromised. Unimportant resources can be protected with weak passwords, which Tippett calls "throwaway" passwords.

For example, some companies provide a wireless access point to give visitors network access. Those companies will want to block access from outsiders looking for a free ride to the Internet, but if outsiders do get onto that network, it's no big deal.

Likewise, you don't need to use a strong password to protect your access to the Cartoon Network web site, said Joseph Grajewski, CEO of Mandylion Labs, which makes password-management products.

But a network manager might require very strong passwords for computers holding resources that are very important, such as nuclear launch codes or, even more importantly, the secret formula to Coke.

The best way to secure important resources is to have fewer than five very strong passwords for administrator-level access. Cracking the passwords would become so time-consuming as to be extremely unlikely.

But how strong is strong enough for a very strong password? Help is available—and you've already paid for it. [url=\"http://csrc.nist.gov/publications/nistpubs/800-63/SP800-63v6_3_3.pdf\"]The National Institute of Standards and Technology has just released a new guide to selecting passwords[/url], covering the four levels of protection necessary, guidelines on how to tell how strong a password is, and how to create a stronger password.

The NIST document is 50 pages. If that's more than you want to know about password's—or if you're looking for something fast to hand out to your users—[url=\"http://csrc.nist.gov/organizations/fissea/presentations/2000/passwrd-guide.doc\"]NIST provides a guide to password creation[/url] and [url=\"http://csrc.nist.gov/organizations/fissea/presentations/2000/password-survey.doc\"]checklist to make sure passwords comply with your policies.[/url]

Very strong passwords should be eight randomly chosen characters consisting of letters, numbers and special characters, Grajewski said.

"I haven't heard from anyone who manages their passwords properly and has an eight-character password that's ever been breached," Grajewski said.

Passwords need to be changed every 60 to 90 days.

Some experts suggest even longer passwords, but those aren't necessary for normal use. "Five percent of logins require greater authentication," Grajewski said. "For that, you use smart cards and extra-long passwords."

Of course, eight-character passwords made of random characters can be very expensive because of the time required to help users who forget them. Also, users will write down login information and lose it.

But Mandylion Labs makes a device about the size of a key chain that's designed to remember your passwords for you.

The device, called the ebpLite, secures passwords by requiring a coded sequence of button presses to display them. Some versions, aimed at the enterprise, can be managed centrally. Consumer versions of the device can be found in a number of places, including at the National Spy Museum in Washington, DC.

Other password managers include dozens available for the Palm through the PalmSource web site. Most are less expensive than the ebpLite, but attackers may be able to get into the password file if they have access to the device.

The device from Mandylion, on the other hand, can be set so that even one incorrect attempt to get in will clear the device and erase its memory. The US government, and especially some three-letter agencies, just love that part.

But can't passwords be replaced by biometrics? Unfortunately, biometric devices have yet to prove themselves to be reliable and inexpensive enough to really replace passwords, although they can play an important role in supplementing passwords. Inexpensive biometrics devices may not be as accurate as they should be, sometimes failing to recognize a valid fingerprint or iris.

Also, while it's easy to replace a lost password, it may not be so easy to replace the body part being recognized by the reader.

And, of course, if the material being protected is valuable enough, there are ways for an attacker to provide the body part being read, even if the attacker doesn't provide the person normally attached to it.

While biometrics may not replace passwords in routine use, there are plenty of uses for them. However, we'll need to look at that issue more completely in a future column.

The bottom line, though, is that passwords by themselves are not a complete solution. It's vital to provide physical security so that would-be crackers can't get close enough to your network to try passwords. It's also vital that you use more than just user names and passwords to secure remote access connections. And while strong passwords do offer some additional security, what matters more is that you require passwords and manage them properly.

Wayne Rash is a writer based near Washington, DC. He was one of the first to create secure networks for the military and for other government organizations, and he has written about security for over twenty years. You can reach him at [url=\"http://mailto:wayne@rash.org\"]wayne@rash.org[/url]. Contact the editor of Security Pipeline at [url=\"http://mailto:mwagner@cmp.com\"]mwagner@cmp.com[/url].

[url=\"http://informationweek.securitypipeline.com/51201573\"][source][/url]