RE: [fw-wiz] Stanford break in

From: Paul D. Robertson (paul_at_compuwar.net)
Date: 04/23/04

  • Next message: Victor Williams: "RE: [fw-wiz] Stanford break in"
    To: Laura Taylor <ltaylor@relevanttechnologies.com>
    Date: Thu, 22 Apr 2004 18:15:30 -0400 (EDT)
    
    

    On Thu, 22 Apr 2004, Laura Taylor wrote:

    > You need some user behavior/rules of engagement policies to deal with users
    > bringing home password files and cracking them. And they should be enforced.
    > Laura

    Ron's main point (I think) is that you can't enforce strong password
    policies everywhere in an organization, so folks who want to circumvent
    those policies will do so, and the net result of stronger passwords is
    lost. Non-trivial passwords, I agree with, but "strong passwords" really
    just piss off users without much overall affect to the organization's
    security posture if there's enough disparate system types (or if users
    simply use that password everywhere so they can remember it.)

    Paul
    -----------------------------------------------------------------------------
    Paul D. Robertson "My statements in this message are personal opinions
    paul@compuwar.net which may have no basis whatsoever in fact."
    probertson@trusecure.com Director of Risk Assessment TruSecure Corporation
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Victor Williams: "RE: [fw-wiz] Stanford break in"

    Relevant Pages

    • Re: Shooters Connection Review- Not So Good
      ... He is a prick about the pocity and loves to enforce it as he makes ... YOU failed to read the policies! ... It seems there was no hassle with your return only a restocking fee taht ... The Attitude seems to be YOURS not Chuck's. ...
      (rec.guns)
    • Re: Express Checkout
      ... Since the stores won't enforce ... these policies, then it's up to the customers. ... back of me mumbling obscenities. ...
      (rec.food.cooking)
    • Express Checkout
      ... Since the stores won't enforce ... these policies, then it's up to the customers. ... back of me mumbling obscenities. ...
      (rec.food.cooking)
    • Re: Can I see when the recipient has opened my email?
      ... Unfortunately, I am not the boss, so I can't enforce it, but thanks anyway:) ... > establish company policies and then enforce them then you deliberately ... > receipts, what action to take, and enforce them. ...
      (microsoft.public.outlook.general)