Re: password expiration
From: Wayne Walton (wayne.walton@s2i2.net)Date: 05/20/02
- Next message: Joshcali: "Commercial Copy Protection SDK?"
- Previous message: Critter: "FS: Book for sale - Internet Security (2nd edition)"
- In reply to: Alun Jones: "Re: password expiration"
- Next in thread: C Colon: "Re: password expiration"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Wayne Walton" <wayne.walton@s2i2.net> Date: Mon, 20 May 2002 21:15:50 GMT
Alun Jones <alun@texis.com> wrote in message
news:TX9G8.24495$NT.3290427543@newssvr12.news.prodigy.com...
> In article <DOYF8.6652$zV.62078@sccrnsc02>, "Blah" <nospam@aol.com> wrote:
> >Yep, "password never expires". However, it is generally considered a Bad
> >Thing to use that in any kind of production environment.
>
> On the other hand, there are _some_ valid uses for it. Let's say, for
> instance, you have a password for your customers to access the current
version
> of your software. Changing the password for this account would mean
> contacting all of your customers. You don't want to have to do this every
> thirty days, you probably really only care about it in one of two cases:
>
> 1) There's been a leak, and the password is widely known, causing large
> numbers of unauthorised downloads (you do monitor your log files, don't
you?)
> 2) There's a new version out, and you don't want the new version to be
made
> available to the people who were licenced to get the old version but
haven't
> paid the upgrade fee.
>
> Even in case 2), you might not want to change the password, but you might
want
> to use a new account.
>
> Alun.
> ~~~~
>
Heh, true enough. As always, there are exeptions to the rule.
>(you do monitor your log files, don't you?)
Actually, I sell and install software that does that for intelligently.
(correlates attacks across a network too)
Wayne
- Next message: Joshcali: "Commercial Copy Protection SDK?"
- Previous message: Critter: "FS: Book for sale - Internet Security (2nd edition)"
- In reply to: Alun Jones: "Re: password expiration"
- Next in thread: C Colon: "Re: password expiration"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|