Password Rotation Policies Under Scrutiny: NIST Guidelines, Historical Origins, and Logical Flaws
The debate over scheduled password changes has resurfaced after a reference to NIST guidance in an earlier article on the Hive Systems password table sparked extensive commentary. NIST recommends changing passwords only when compromise is detected rather than on a calendar basis. Critics raised several objections: public breach databases are incomplete, scheduled rotation limits the window for offline hash cracking, it terminates unknown active sessions, and user inconvenience is not a valid reason to abandon good hygiene.
The author argues that these discussions often follow flawed reverse logic. Proper security design, as outlined in FSTEC Russia Order No. 117, GOST R ISO/IEC 27001, and the FSTEC threat assessment methodology, begins with threats and then selects controls. In contrast, many defenses of 90-day rotation start with the existing policy and then construct hypothetical scenarios to justify it.
This reverse approach can justify almost any measure. Requiring password changes every 12 hours or never changing them at all can both be "proven" useful by inventing suitable threats. The author proposes a practical test: state the conditions under which the control would be considered unnecessary. If such conditions cannot be formulated, the measure is being rationalized rather than justified.
A key distinction is drawn between leakage and compromise. Leakage is an objective event in which secret information becomes known to unauthorized parties. Compromise is the loss of grounds for trusting that the secret remains known only to authorized persons. NIST and FSTEC documents therefore require replacement when there is reason to doubt secrecy, not only when an actual leak is proven. Internal signals such as personnel changes, workstation incidents, or anomalous logins often provide stronger indicators than external breach repositories.
The 90-day figure is frequently attributed to the 1985 U.S. Department of Defense "Green Book" (CSC-STD-002-85). Examination of the document shows the claim is incorrect. The Green Book models password lifetime as an input parameter rather than a derived result and demonstrates that extending the lifetime from six months to a year changes the required password length by only a fraction of a character. The authors explicitly state that lifetime is not a critical factor provided the password is changed at least annually.
Crucially, the Green Book calculations assume an online attack with rate limiting. When a password hash database is stolen, the guessing rate increases by many orders of magnitude and the model no longer applies; only increased password entropy (length and complexity) remains effective. This limitation was already recognized in 1985.
PCI DSS v4.0 requirement 8.3.9 now permits organizations to replace the 90-day rotation mandate with continuous monitoring and dynamic analysis of account behavior. The article concludes that scheduled rotation is only defensible when detection capabilities are absent; once proper monitoring exists, targeted changes upon detected compromise are strictly superior.
Related articles
OBEP Raids on Russian IT Firms: How to Safeguard Source Code, Servers and Blockchain Assets During Searches
Russian IT companies, Web3 projects and fintech services now face frequent visits from OBEP operatives conducting pre-investigative checks or searches under criminal cases. The article details the legal distinction between operational-search measures and formal searches, emphasizing article 164.1 of the UPK RF that prohibits seizure of physical servers in economic crime investigations. It explains how companies can demand data mirroring instead of hardware removal and how to invoke article 51 of the RF Constitution when pressured for encryption keys. Commercial secret regimes are presented as a tool to raise criminal liability for leaks and to request closed court proceedings. Practical checklists cover document verification, staff instructions, password retention and immediate calls to specialized criminal counsel. The guidance aims to prevent business paralysis while preserving evidence integrity during raids.
RWB Deploys Enterprise-Wide Database Access Control with Trino and Open Policy Agent
RWB has replaced fragmented manual database access processes with a centralized architecture built on Trino as the single entry point and Open Policy Agent for policy enforcement. The system enforces least-privilege access, mandatory auditing, and automated revocation tied to HR records while eliminating anonymous and password-based logins. Access requests now complete in 3–10 minutes instead of an average of four days, with 92 percent handled automatically. Key components include Keycloak for OIDC authentication, Vault for secrets, Kafka for security event streaming to SOC, and Kubernetes orchestration. Responsibility is split across AI & Data Security, Core DevOps, Access Management, SOC, and Trust & Safety teams. More than 1,250 PostgreSQL clusters and 90 projects are now connected, with real-time dashboards tracking adoption and policy health.
Russia Moves to Allow Biometric Data Processing for Suspects and Convicts Without Consent
Russian law enforcement agencies may soon gain the legal right to process biometric data of suspects, accused individuals, and convicted persons without requiring their personal consent. A corresponding draft bill has already been submitted to the government and is scheduled for review at the next cabinet meeting, according to TASS. The measure covers fingerprints, facial images, voice recordings, and other physiological or behavioral characteristics used for identification. If approved, prior permission from the individual will no longer be needed when biometrics are used in criminal proceedings. The change applies not only to those already convicted but also to suspects and accused persons whose guilt has not yet been established by a court. For ordinary citizens, enrollment in the Unified Biometric System remains voluntary and is used for remote identity verification when accessing financial and government services.
FAS Clears Russian Operators on 'Unlimited' Internet Claims Despite Speed Throttling to 128 Kbit/s
The Federal Antimonopoly Service has declined to investigate complaints regarding promises of unlimited internet and unrestricted roaming access made by major Russian mobile operators. The Association of Professional Users of Social Networks and Messengers argued that operators including Vimpelcom, MegaFon, MTS, and T2 Mobile mislead customers by advertising unlimited plans while throttling speeds to 128-512 Kbit/s after data caps are reached. FAS determined that information on official company websites does not qualify as advertising under Russian law. Operators maintain that the term unlimited remains accurate because no total data volume limit exists, only speed reductions detailed in service descriptions. The complainants and legal experts contend that FAS reviewed only technical parameter pages and ignored banners, promotional news, search ads, SMS, and push notifications that may meet legal criteria for advertising. The decision leaves consumers facing slow connections unsuitable for video or file downloads after initial allowances are exhausted.