Passwords are so last century … but some still swear by them

Opinion
Oct 4, 20062 mins

* What's your password policy?

If you follow NCAA college football, you’re probably aware that Penn State’s head coach, Joe Paterno, has been in that job seemingly forever. When he was named head coach, it was the same year Bob Metcalfe invented Ethernet (1973)! And Paterno had already been an assistant there for 16 years, starting in the PSU coaching staff in 1957 (the year FORTRAN was created). There are many who believe his coaching methods and style are mired in the mid-nineteenth century.

Now it appears that Penn State’s IT department – at least its security practices – might be stuck in the same time warp as Paterno’s coaching.

As headlined by Penn State Live, the school’s own news syndicator, “University implements yearly password change initiative”!

That’s right, as outlined by Kevin Morooney, Penn State’s newly appointed vice provost for Information Technology, “All individuals who currently have a Penn State Access Account will need to ensure that they change their password at least once every 365 days under this new plan. It’s important to change your password often, and it’s critical for the University to ensure the greatest security in the community environment.”

Well, at least he got the part about it being critical to change your password “often.” Nowadays, though, “often” can mean “every time you log in.” One-time-passwords (OTP – full explanation here) are now used in many mid- to high-security environments. Even consumer-oriented online banking sites (at least in Europe) frequently use OTP to strengthen security.

Twenty years ago, the recommendation of security experts was that a user should be forced to change passwords every 45-days or so. Today, most security experts recommend doing away with passwords entirely. Even those not known for their security prowess can chant the litany: “The password is dead” (as cited by Bill Gates).

Penn State’s password initiative is about as modern and up-to-date as its football team’s offense. But what about your password policy? Do you still have passwords? Do you allow users to create and change them and to a particular schedule? When was your last security breach from either a hacked password, a stolen password or a “borrowed” password? Are you sure – what systems are in place that let you know when there’s been a password misuse? Maybe it’s time you started your own password initiative.