Re: remote desktop issues



In message <OZ7wNYOAIHA.4164@xxxxxxxxxxxxxxxxxxxx> "S. Pidgorny <MVP>"
<slavickp@xxxxxxxxx> wrote:

Fair enough. The thing is that the requirement of "sufficient" passphrase
_is_ a form of password complexity requirement. Not easily enforced - ask
for 48-character long password, and you'll get a lot of "Paaaa..aaasword1"
as the passwords.

Yeah, true enough. It takes user education as much as anything else.

I'd be interested in requiring passphrases (requiring there to be at
least 5 different dictionary words, for example) as a possible solution
to users creating stupid passwords.

Some users will end up with similar passwords, true enough, but it will
change the scope of brute forcing anything.

My choice is strong authentication, like a smart card. The alternative
(sozialist approach) is to have passwords centrally assigned by Politburo.

What you have, instead of what you know. I'm less thrilled with that,
since it means if I lose the smartcard, access is compromised until I
notice.

If you combine it with a password, we're back to the same problem above
(although obviously we've raised the bar pretty significantly -- I'm not
knocking smartcards, just pointing out that they aren't a replacement
for passwords)

--
You can get more with a kind word and a 2x4 than just a kind word.
.



Relevant Pages

  • Re: US Military bans HTML in emails
    ... up the mess. ... You mean like requiring 6-character passwords to now be "complex"? ... Or as in email scanners that removes all EXE, ... It turns out that you get a lot more bang for the buck by requiring ...
    (comp.os.vms)
  • Re: non-interactively mount windows-based network shares at login
    ... >> network shares at login without requiring the user to provide their ... of passwords are, and make sure I update the files every time a password ...
    (Fedora)
  • Re: Log In Security
    ... > I want to start requiring 8 characters minimum, ... contain at least one capital letter and one ... I also want to require that passwords be changed ...
    (comp.security.unix)
  • AutoComplete password doesnt work
    ... I've always checked the box to allow the computer to save my passwords; however, it keeps on asking me to enter my password each time nevertheless. ... The autocomplete option for passwords is on. ... How do I get it so that I can save my passwords without requiring me entering them each time? ...
    (microsoft.public.windowsxp.security_admin)