Whitepaper-Password-Guidelines_EN
Whitepaper-Password-Guidelines_EN
Risik Analysis 4
Conclusion 10
Introduction
More and more security experts are of the opinion that prescribed pass-
word guidelines are more likely to harm than benefit the IT security of
companies. The German Federal Ministry for Information Security (BSI) now
advises against fixed minimum requirements for the complexity and length
of passwords, as well as against changing them regularly.1 The National
Institute of Standards and Technology (NIST) has also withdrawn its former
recommendation to change passwords every 90 days and has scaled down
its complexity requirements. 2
3
Risik Analysis
In order to create transparency about the type and extent of potential risks
posed by password policies in practice, the first step is to define the requi-
rements for a secure password and how to deal with them. Subsequently,
possible causes for a paradigm shift are identified and evaluated.
ABC 123 !?$ Don‘t be stingy with: Upper and lower case letters,
numbers and special characters
4
The password should contain special characters, numbers and alternating
have upper and lower case letters and does not contain words from the dic-
tionary. No-Go`s are rows of numbers and letters and keyboard patterns. So
far, it was also suggested to change the password after a certain time. 3
5
Insecure Workarounds in Practice
When employees are overwhelmed, password policies grasp at nothing. In-
stead, they resort to insecure means that are often not even known to inter-
nal IT. According to the market research company Ipsos, one in two people
memorize their own passwords. So in the first case, no secure password is
created in the first place. 5
In the second case, the employee creates a complex password. However, sin-
ce they are difficult to remember, 1 in 5 simply write it down and
use it for several services at the same time. 5 Equally popular as dangerous
are also homemade solutions such as storing in the browser or in insecure
documents like Excel lists. Only 1 in 3 changes his password regularly. If the
password does change, tricks are used by replacing or appending only one
character.
As a result, the German Federal Office for Information Security (BSI) this year
abandoned precise minimum specifications for password creation and now
recommends a length of 8 to 25 characters in combination with two to four
character types.1 The following applies: The shorter, the more complex and vice
versa. NIST also refers in its amendment to the fact that research has shown
that users would make very predictable changes to their passwords by giving
precise specifications such as simply appending a special character.2
Since companies often do not learn at all or only too late if their access
data falls into the wrong hands, the recommendation to change pass-
words only in the event of loss or data theft is no longer valid. A regular
exchange of passwords is still necessary because the risk of compromise
increases with the duration of use.
6
Since the causes for the improper handling of passwords result from too high
requirements, the paradigm shift of the BSI is rather to be classified as out
of necessity. Even if the purpose of relieving users was well-intentioned, not
changing passwords does not solve the security problem. The security risk
is more likely to be aggravated if clear instructions are not communicated to
employees.
Risk Assessment
without Password Policies
If you can‘t immediately answer these questions wit a clear „yes“, password policies can actually worsen
IT security in your organization:
Are you sure that your employees don‘t use insecure workarounds such as saving
passwords in the browser or sharing them via chat and e-mail?
Can you prevent your employees from (re)setting insecure passwords on their own?
Do you still have an overview of all login services and passwords in the company?
From the analysis it follows that it is not password policies that are respon-
sible for employees resorting to insecure workarounds, but the lack of tools
and processes. Properly applied, password policies in combination with a
password management solution provide essential protection for companies.
Not having to change passwords on a regular basis does not get to the heart
of the problem, nor does it provide greater security. Rather, it can lead to
even worse passwords being used over a longer period of time, giving atta-
ckers more time to guess them.
7
Even with highly complex passwords, a
constant exchange is essential to keep
attackers out and close security gaps.
Sascha Martens, CTO MATESO
8
This way, highly complex passwords are created in seconds and, ideally, auto-
matically stored in the corresponding Password Manager and managed for
login. This means that the employee does not even know the password, but
can still log in securely via single sign-on. The role-based assignment of rights
allows employees to use passwords only for login, edit them or share them
securely with colleagues.
Security policies regarding minimum length and complexity can also be pre-
defined for automatic password generation using a password manager. The
assignment of individual security levels and the restriction of authorizations
also ensures that particularly sensitive accounts and accesses are protected
according to their requirements.
Password Managers can also help to increase the security awareness of emp-
loyees: Notifications in the software alert them if their assigned password is not
strong enough to automatically prompt them to set a new, better password,
for example. This means that users are not left alone when creating passwords
and do not even get the idea of resorting to even less secure means out of
necessity.
We recommend combining the introduction of password policies with the following protection measures:
Evaluate the security level of existing password creation and management mechanisms.
Ensure that every employee understands the necessity and correct implementation
of password policies.
*****
The perfect Password should ...
be entered
automatically.
***** best not be known
by anybody!
***** ?????
So you‘d better give your employees valuable tips and provide them with a
password manager for implementation. In addition, a concrete security expert is
essential in order to always involve the employees in the password management
process, to educate them and thus prevent the emergence of insecure solutions
such as „Password1“ and Excel lists.
Author:
Kristina Kaya
Product Marketing Manager
Sources:
1
Bundesamt für Sicherheit in der Informationstechnik 2020; Empfehlungen: https://www.bsi-fuer-buerger.de/
BSIFB/DE/Empfehlungen/Passwoerter/passwoerter_node.html
2
National Institute of Standards and Technology 2020; Digital Identity Guidelines: https://www.nist.gov/itl/tig/
projects/special-publication-800-63
3
Bundesamt für Sicherheit in der Informationstechnik; Pressebereicht 2011: https://www.bsi.bund.de/DE/Presse/
Pressemitteilungen/Presse2011/Passwortsicherheit_27012011.html
4
Der große Passwort-Stress, YouGov: https://de.statista.com/infografik/7705/der-grosse-passwort-stress/
5
Deutschland; Ipsos; 1.000 Befragte; ab 18 Jahre; Internetnutzer, die in den letzten drei Monaten etwas online
gekauft haben; Online-Umfrage: https://de.statista.com/statistik/daten/studie/3609/umfrage/uebersicht-ue-
ber-eigene-online-passwoerter/
6
Bundesamt für Sicherheit in der Informationstechnik 2020: https://www.bsi.bund.de/DE/Themen/ITGrund-
schutz/ITGrundschutzKompendium/bausteine/ORP/ORP_4_Identitäts-_und_Berechtigungsmanagement.html
7
Süddeutsche Zeitung 2020; Die Qual des ständigen Passwort-Wechsels endet: https://www.sueddeutsche.de/
digital/passwort-wechseln-bsi-1.4784293 10
MATESO is a leading German IT company, which has successfully established
in the DACH region since the company was founded in 2006. The developed
password security solution Password Safe is distributed internationally by its
worldwide partner network. Well-known references testify to the technologi-
cal and know-how advantage of the IT software.
Today the constantly growing enterprise registers over 10,000 corporate cus-
tomers with several million users worldwide - including 20 Dax 30 companies.
Password Safe serves companies as a central digital safe for securing, ma-
naging and monitoring sensitive data such as passwords, documents and
secrets.
In dealing with
passwords, humans
are still indispensa-
ble.