Re: Passwords On Paper

From: Zeshan Ghory (zeshan.ghory@btinternet.com)
Date: 12/15/01


Date: Fri, 14 Dec 2001 23:06:34 +0000
From: Zeshan Ghory <zeshan.ghory@btinternet.com>
To: security-basics@securityfocus.com

On Thu, Dec 13, 2001 at 02:29:44PM -0500, ProfesseurWoo@aol.com (ProfesseurWoo@aol.com) wrote:
> Is anyone familiar with a government or private study that surveyed the top 10 places to store
> passwords that were written down on paper; e.g. under the keyboard, etc?

I would imagine that it would be very difficult to obtain enough
information to carry out such a survey effectively.

Personally, I have certainly seen passwords (with corresponding
user names) written on post-it notes stuck to monitors, on
whiteboards, and sometimes just scribbled down on random bits of paper
lying on a desk.

This is much more likely to occur if people are *given* passwords
instead of choosing their own.

Zeshan



Relevant Pages

  • Re: Decrypt
    ... that you store the encrypted passwords on the server. ... In fact, don't just hash the passwords, but combine the password ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: How to test that I configured httpd+Subversion wirh Path Based Authorization in the right way?
    ... client, 'svn', stores all passwrds locally in cleartext. ... MUAs or FTP passwords? ... And other VCS-es store their passwords ...
    (comp.os.linux.security)
  • [OT] Secure storage
    ... user names and passwords on a Windows XP computer? ... I'm looking for an application that will store the data in a way that isn't ... I'm just trying to find a good way to store my various usernames and ... I used to have a nifty little app on my PDA called Memorizer which used ...
    (comp.lang.java.programmer)
  • Re: Windows Authentication (asp.net 1.1 C#)
    ... it is up to you how you store your passwords - FormsAuth is just a mechanism ... Usually you store the passwords in a database using salted hashes - have a look at PasswordDeriveBytes class ... Authentication or Form Authentication. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: secure storage in Active Directory
    ... AD does not store user account passwords - it stores a hash of ... > I understand that the Active Directory stores user data and passwords. ... > How does it store these securely within its internal structure? ... they store the password hash. ...
    (microsoft.public.security)