Re: Linking Password Length to Write-down probability

Doug.Janelle_at_Thermo.com
Date: 05/27/05

  • Next message: Gonzalo Martinez: "Re: Leaving a door open?"
    To: security-basics@securityfocus.com
    Date: Fri, 27 May 2005 12:34:12 -0400
    
    

    In the real world, we have to acept that, not matter how
    easy we try to make it for them to remember passwords,
    users *will* write them down. In these cases, I encourage
    them to at least obfuscate things a bit...don't make it obvious
    what they mean. (IOW: for G**'s sake don't write
    "ID=myname, PW=Free4All".)

    ID's are usually easy(er) to remember, so just write the
    password w/o the "PW=". Throw in an extraneous character
    or two...leave one or two characters out...transpose several
    characters...anything to make the written data useless to
    anyone who might come across it.

    dcj2

    >He claims that prohibiting users from writing down their
    >passwords is bad for security. His main point is that if users are
    >prohibited from writing down their passwords, they will use the same
    >easy to guess password everywhere.


  • Next message: Gonzalo Martinez: "Re: Leaving a door open?"

    Relevant Pages

    • Re: Question about magnets
      ... forces and name three states of matter. ... ocean on an unlabled map, their anniversary, ... But, yeah, I forget my passwords too and since I ... I seem to remember something about half the students at the University ...
      (alt.home.repair)
    • Re: Question about magnets
      ... It does bite my butt that few adults can answer two simple question, Name three natural forces and name three states of matter. ... That very basic information about the world we live in isn't taught in schools or at least it isn't taught in a manner that students retain or understand it. ... But, yeah, I forget my passwords too and since I don't expect any break-ins to steal my passwords, I write them down. ...
      (alt.home.repair)
    • Re: Tracking down the IP address of attempted hackers
      ... It's only a matter of time if... ... You don't have account lockout ... You don't use passphrases instead of passwords ... And you change them on a somewhat regular basis ...
      (microsoft.public.backoffice.smallbiz2000)
    • Damn, the traveling relativity twin cant login to his computer account.
      ... A network admin named Eric is told employees must change ... I told you I want them to change passwords every 30 days no matter what. ... Eric says time dilation Sir. ...
      (sci.physics)
    • Re: 10.5 Tip: Custom Dock for the guest account
      ... System Preferences? ... I don't want guests in there. ... If your passwords are set up properly, it shouldn't matter at all. ...
      (comp.sys.mac.system)