Re: Linking Password Length to Write-down probability

From: Nick Owen (nowen_at_wikidsystems.com)
Date: 05/27/05

  • Next message: Dan Tesch: "Re: Linking Password Length to Write-down probability"
    Date: Fri, 27 May 2005 11:44:31 -0400
    To: Stian Øvrevåge <sovrevage@gmail.com>
    
    

    I think it would be hard to link writing down passwords to just the
    length and complexity. I would think that the number of passwords a
    person has would be a bigger factor. I think it would be hard to
    account for that - since so many would be outside the enterprise.

    Stian Øvrevåge wrote:
    > God morning list!
    >
    > I continually read papers which advertise increased password lenghts (
    > and outrageous complexity requirements ) as The Solution(TM). I work
    > in a fairly large organization and I can safely acknowledge that even
    > 8 character passwords with moderate complexity requirements are VERY
    > prone to beeing written un-encrypted and un-hashed on Post-Its, and
    > then safely contained, under the keyboard, or on the monitor. Which in
    > my humble oppinion is bordering to "stupid security".
    >
    > I'm certain that there is a link between required password lenght and
    > complexity and the probability of users taking the huge leap backwards
    > and writing passwords down.
    >
    > I've been doing a little Googling, but I can't seem to find any
    > scientific analytical/statistical research done on this particular
    > subject. Is anyone out there aware of any works done in this field? If
    > not, is there anyone intrested in conducting such a survey on the
    > behalf of the community?
    >
    > Regards, Stian
    >

    -- 
    Nick Owen
    WiKID Systems, Inc.
    404.962.8983 (desk)
    404.542.9453 (cell)
    http://www.wikidsystems.com
    At last, two-factor authentication, without the hassle factor
    

  • Next message: Dan Tesch: "Re: Linking Password Length to Write-down probability"

    Relevant Pages

    • Re: Passwords
      ... > the complexity requirements. ... > of passwords that no user can use. ... >>MVP for Windows Server - Software Distribution ...
      (microsoft.public.windows.server.general)
    • Re: Password Quality checker
      ... for the complexity you are looking for. ... On our web apps at work it ... have met the proper complexity requirements. ... whether the passwords they choose meet the organization's policy. ...
      (Security-Basics)
    • Re: Passwords too complex on Server 2003
      ... You can't disable the GPO Default Domain Policy to disable complexity ... passwords, within this policy you have set a setting to disable complexity ...
      (microsoft.public.win2000.active_directory)
    • Re: Reasons and examples for security
      ... setting pwd length large enough to literally force passphrase use. ... of complexity). ... >> otherwise compromised passwords by invalidating them. ... >>> I am looking for examples to support my case for tighter security. ...
      (microsoft.public.security)
    • Re: Passwords
      ... of passwords that no user can use. ... >can tie the complexity with other available options, ... >> How do you modify the parameters for password policies? ... I chose to use the complexity requirements ...
      (microsoft.public.windows.server.general)