Passwords In Perpetuity
There have been plenty of prognosticators over the past few years who have predicted the demise of the password in 5, 10 or 15 years. But for now, infosec professionals will continue to have to deal with passwords and all of their attendant headaches. Users create insecure passwords, IT chides them and they just keep doing it. So IT security starts enforcing password policies and escalating every time they don't seem to be making a difference.
"Security professionals often keep solving with stronger versions of the same controls," says Lucas Moody, CISO of Palo Alto Networks. "'Let’s go from 8 character minimum passwords to 12 character minimum passwords. That isn’t quite doing it? Let’s enforce 30 character passwords.'"
Image Source: Adobe Stock