Re: On password expiration
- From: "Shenan Stanley" <newshelper@xxxxxxxxx>
- Date: Fri, 31 Mar 2006 01:34:01 -0600
Shieldfire wrote:
In another group I posted a question on security for some of our
external users. They will access a messaging system (not MS
Exchange) and I wanted to set their passwords to expire every N
days.
Lots of admins on that group argue that this is an evil thing. If
user Joe already has a secure password it is evil to make him
change it and possibly come up with a weaker password after N days.
The consequences for my users on this system may be extreme if the
passwords are compromised.
How do you argue, to expire or not expire - that's the question.
Expire. The longer a password is the same, the greater chance it can be
compromised.
As far as making a less complicated password - that all depends on your
complexity requirements.
--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html
.
- References:
- On password expiration
- From: Shieldfire
- On password expiration
- Prev by Date: On password expiration
- Next by Date: Re: Encryption
- Previous by thread: On password expiration
- Next by thread: Re: On password expiration
- Index(es):
Relevant Pages
|
|