Discussion on best practices for password management

  • 16 April 2014
  • 1 reply
  • 13 views

Userlevel 2
Hi, folks,
 
In wake of the HeartBleed bug, I'm getting some belated education about web security. In my reading I have not seen a complete concensus on recommendations for password management.
 
https:///t5/Security-Industry-News/Hacked-LinkedIn-eHarmony-and-Last-fm-How-did-this-happen-and/m-p/5790 for instance.

 
These points made by the OP are uncontested:
  • Create a strong password
  • Have different passwords for different sites
  • Change your password immediately when notified of any breach
 
But I've seen varied advice on this point:
  • Change your passwords every 90 days
 
The argument is that with strong passwords and two-factor authentication it is not necessary to frequently change passwords. I've even seen some discussion that requiring frequent changes is counterproductive, as it discourages use of strong passwords.
 

I would appreciate any insights into these or other best practices for password management from the Webroot community. If you have favored sources of (online) information on this topic, I will follow through on anything you share.

Thanks in advance,
 
LauraB

1 reply

Userlevel 7
Badge +56
What I'd add is that using a password manager makes things a heck of a lot easier.  I only change my passwords when I have reason to (or I'm forced to by policy), but frequent changes can't hurt.  Having a way to manage those and not remember them takes some of the pain out of it.

Reply