Re: How to tell a user their password?

From: Colin B. (cbigam_at_somewhereelse.nucleus.com)
Date: 10/22/04

  • Next message: David H. Lipman: "Re: How secure are passwords in TweakUI autologon?"
    Date: Thu, 21 Oct 2004 22:27:23 GMT
    
    

    In comp.security.unix Western Larch <larix_occidentalis@yahoo.com> wrote:
    > Hi,
    >
    > What's considered good practice about telling users
    > their passwords? Any kind of a scheme that involves
    > writing it down or saying it out loud has the potential
    > (if you're paranoid -- ha ha, only serious) for
    > looking over the shoulder or eavesdropping.
    >
    > Are there schemes for revealing passwords such that
    > even if the password is compromised, the effect is
    > harmless?

    Give them a default password, expire it immediately, and force them to
    change it on the spot.


  • Next message: David H. Lipman: "Re: How secure are passwords in TweakUI autologon?"

    Relevant Pages

    • Re: Password variation scheme a plus in security?
      ... Unless your scheme is easily guessable, or I have grabbed two or more of your passwords along with the sites you use them on, you don't have nearly as much to worry about. ... immediately successful logins, ... and from these maybe 90.000 give them immediate login success ...
      (Security-Basics)
    • Re: k-deterministic public-private key generation
      ... I won't disagree with your evaluation of this scheme in context of ... input to a PK generation scheme, ... Your point about remembering passwords that aren't entered ... and 3) protect against attacks on the key pair from even ...
      (sci.crypt)
    • Re: How to tell a user their password?
      ... In comp.security.unix Western Larch wrote: ... > What's considered good practice about telling users ... > their passwords? ... Any kind of a scheme that involves ...
      (comp.security.unix)
    • Re: admin account password management
      ... and utterly obscure to anyone else. ... match to create a password scheme. ... safe to store passwords and or system/network information on either. ... >All your favorites on one personal page – Try My Yahoo! ...
      (Security-Basics)
    • Re: Word 2000
      ... >> case, lower case letters, numbers and special characters. ... > I have read that it is quite possible to break the passwords on users ... default scheme in Office, not in Windows. ... the hacker just needs to crack the Windows passwords to gain access ...
      (microsoft.public.security)