Not Using Password Aging |
Weakness ID: 262 (Weakness Variant) | Status: Draft |
Description Summary
Scope | Effect |
---|---|
Authentication | As passwords age, the probability that they are compromised grows. |
Example 1
A common example is not having a system to terminate old employee accounts.
Example 2
Not having a system for enforcing the changing of passwords every certain period.
Phase: Architecture and Design Ensure that password aging functionality is added to the design of the system, including an alert previous to the time the password is considered obsolete, and useful information for the user concerning the importance of password renewal, and the method. |
The recommendation that users change their passwords regularly and do not reuse passwords is universal among security experts. In order to enforce this, it is useful to have a mechanism that notifies users when passwords are considered old and that requests that they replace them with new, strong passwords. In order for this functionality to be useful, however, it must be accompanied with documentation which stresses how important this practice is and which makes the entire process as simple as possible for the user. |
Nature | Type | ID | Name | View(s) this relationship pertains to![]() |
---|---|---|---|---|
ChildOf | ![]() | 255 | Credentials Management | Development Concepts (primary)699 |
ChildOf | ![]() | 404 | Improper Resource Shutdown or Release | Research Concepts (primary)1000 |
ChildOf | ![]() | 693 | Protection Mechanism Failure | Research Concepts1000 |
PeerOf | ![]() | 263 | Password Aging with Long Expiration | Research Concepts1000 |
PeerOf | ![]() | 309 | Use of Password System for Primary Authentication | Research Concepts1000 |
PeerOf | ![]() | 324 | Use of a Key Past its Expiration Date | Research Concepts1000 |
Submissions | ||||
---|---|---|---|---|
Submission Date | Submitter | Organization | Source | |
CLASP | Externally Mined | |||
Modifications | ||||
Modification Date | Modifier | Organization | Source | |
2008-09-08 | CWE Content Team | MITRE | Internal | |
updated Common Consequences, Relationships, Other Notes, Taxonomy Mappings | ||||
Previous Entry Names | ||||
Change Date | Previous Entry Name | |||
2008-04-11 | Not Allowing Password Aging | |||