HabrAugust 3, 2026🇷🇺Translated from Russian

Password Rotation Policies Under Scrutiny: NIST Guidelines, Historical Origins, and Logical Flaws

The debate over scheduled password changes has resurfaced after a reference to NIST guidance in an earlier article on the Hive Systems password table sparked extensive commentary. NIST recommends changing passwords only when compromise is detected rather than on a calendar basis. Critics raised several objections: public breach databases are incomplete, scheduled rotation limits the window for offline hash cracking, it terminates unknown active sessions, and user inconvenience is not a valid reason to abandon good hygiene.

The author argues that these discussions often follow flawed reverse logic. Proper security design, as outlined in FSTEC Russia Order No. 117, GOST R ISO/IEC 27001, and the FSTEC threat assessment methodology, begins with threats and then selects controls. In contrast, many defenses of 90-day rotation start with the existing policy and then construct hypothetical scenarios to justify it.

This reverse approach can justify almost any measure. Requiring password changes every 12 hours or never changing them at all can both be "proven" useful by inventing suitable threats. The author proposes a practical test: state the conditions under which the control would be considered unnecessary. If such conditions cannot be formulated, the measure is being rationalized rather than justified.

A key distinction is drawn between leakage and compromise. Leakage is an objective event in which secret information becomes known to unauthorized parties. Compromise is the loss of grounds for trusting that the secret remains known only to authorized persons. NIST and FSTEC documents therefore require replacement when there is reason to doubt secrecy, not only when an actual leak is proven. Internal signals such as personnel changes, workstation incidents, or anomalous logins often provide stronger indicators than external breach repositories.

The 90-day figure is frequently attributed to the 1985 U.S. Department of Defense "Green Book" (CSC-STD-002-85). Examination of the document shows the claim is incorrect. The Green Book models password lifetime as an input parameter rather than a derived result and demonstrates that extending the lifetime from six months to a year changes the required password length by only a fraction of a character. The authors explicitly state that lifetime is not a critical factor provided the password is changed at least annually.

Crucially, the Green Book calculations assume an online attack with rate limiting. When a password hash database is stolen, the guessing rate increases by many orders of magnitude and the model no longer applies; only increased password entropy (length and complexity) remains effective. This limitation was already recognized in 1985.

PCI DSS v4.0 requirement 8.3.9 now permits organizations to replace the 90-day rotation mandate with continuous monitoring and dynamic analysis of account behavior. The article concludes that scheduled rotation is only defensible when detection capabilities are absent; once proper monitoring exists, targeted changes upon detected compromise are strictly superior.

Related articles

AntiMalwarePolicy & Regulation

Yandex Alice AI Replaces VK Marusya in Russia's Mandatory Preinstalled Apps List for 2027

Russian authorities have approved the official list of software that device manufacturers and sellers must preinstall on smartphones, tablets, and computers starting in 2027. The updated requirements maintain most of the previous selections without major disruption. The only notable change involves voice assistants, where Yandex Alice AI will now take the place previously held by VK Marusya. This adjustment reflects ongoing government efforts to promote domestic software through mandatory preinstallation policies. The regulation continues to focus on ensuring Russian-developed applications receive prominent placement on new devices sold in the country.

AntiMalwarePolicy & Regulation

FSB Russia Certifies Rutoken Chip 3127 with Five-Year Cryptographic Key Validity

Aktiv has received an FSB Russia certificate for the embedded Rutoken Chip 3127 microcontroller under security classes KS1 and KS2. The certification followed additional research that extended the validity period of the device's private cryptographic keys to five years. The chip belongs to the Rutoken ECP 3.0 3127 product line and targets long-term cryptographic protection in servers, ATMs, workstations, tablets, biometric systems, industrial equipment, and IoT devices. It stores keys in non-extractable form, performs user and device authentication, verifies component integrity, and supports trusted boot processes by controlling executable code at each stage. Additional capabilities include data encryption, derivation of session keys, secure software updates, and protected TLS and VPN connections using the CRISP protocol that complies with GOST R 71252-2024. The chip incorporates hardware-level defenses such as voltage monitoring, protective layer detection, and dummy branch execution to counter physical tampering and side-channel attacks. Pilot deployments have already occurred, including integration into the OVISION biometric access control systems, paving the way for serial use in critical infrastructure.

AntiMalwarePolicy & Regulation

Durov's Addition to Terrorist List Triggers Russian Account Blocks but Does Not Automatically Ban Telegram or Classify Transfers as Terrorism Financing

Russian financial institutions must suspend operations on Pavel Durov's domestic accounts following his inclusion in the Rosfinmonitoring terrorist and extremist list on July 30. The restrictions primarily target his personal finances and property inside Russia, as confirmed by attorney Dmitry Roshchin. Telegram itself remains unaffected as a platform because the messenger and its founder are legally distinct entities. Transfers to Durov do not automatically constitute terrorism financing; criminal liability requires proof that the funds were specifically intended for terrorist activities. The FSB has accused Durov of aiding terrorism by failing to remove channels allegedly used by Ukrainian services for sabotage planning, yet he has not been convicted by a court. Media outlets RIA Novosti and Izvestia reported these clarifications on compliance with Russian anti-terrorism legislation.

AntiMalwarePolicy & Regulation

Russian Ministry Proposes Mandatory Phone-Number Authentication for Foreign Websites and Apps

The Russian Ministry of Digital Development has drafted new rules requiring foreign websites and applications to authenticate users in Russia exclusively through phone numbers. The measure forms part of the third anti-fraud package known as Antifraud 3.0 and would eliminate email, social-media logins and other traditional methods. Foreign service operators would also be obliged to retain registration, login and account-deletion records for three years and to hand them over to Russian law-enforcement agencies upon request. Amendments are planned for Article 8 of the law On Information, with submission to the State Duma scheduled for autumn 2026. Experts warn that many international companies may refuse to build separate authentication flows for the Russian market, potentially leading some services to exit Russia entirely. The proposal also raises enforcement questions for already-blocked platforms such as Facebook and Instagram owned by Meta.