Horrible Ideas in Computer Technology

at around evening time on Sunday, the 6th of January 2008 by Chad

Lets talk… passwords.

Why does everyone hate password policies?  Because of the security people who write the policies.  Its the laws of unintended consequences.

Security guys would love to make you change your password every week, at least.  And have it be 16 characters long full of weird symbols and such.  So they tighten up things as much as they can get away with.  User hassle is NOT THEIR PROBLEM you see.  They’ve said that to me.  That they are proud that they work to the detriment of the user community.

image

And then you do the obvious thing and make really good use of the post-it notes on your desk.

I’ve been doing this tech stuff a very long long time.  And I’m incredibly well versed in security.  And I have a password or two written on a post-it note on my desk because it is impossible to remember the damn thing.  This particular password the security policy won’t let me change to something I’d know.

Now, which would you be willing to do for a good password? 

  • Change it constantly, constantly forget what you changed it to, losing time while waiting on the help desk to reset your password, write it down under the keyboard. 
  • Or use a nice long password, 24 characters or longer.   A pass phrase or sentence.  But one that you maybe change once a year at most.  And that every system at work will let you use.  Something you can remember easily because you don’t have to change it.
  • What is 4 numbers long and is the most important thing to you?  Something much more important than any access to any system you may have at work?  Your PIN number for your bank account.  4 numbers.  That’s it.

Yeah… number 1 is your current state of affairs at just about any company.  I can easily deal with the second option.  You use a nice long password but you can remember it easily.  Or just use the third option, because if a cracker gets a hold of the password database, they’ll have every password cracked in a few days using a single computer, so its a hopeless game anyway. 

If you’re talking national security that’s one thing.  Anything less though…

[del.icio.us] [Digg] [Facebook] [MySpace] [Sphere] [StumbleUpon] [Technorati] [Windows Live] [Email]
1 Star2 Stars3 Stars4 Stars5 Stars
(No Ratings Yet)
Loading ... Loading ...

Related Posts

One Response to “Horrible Ideas in Computer Technology”

  1. Firehand Says:

    At one point we were dealing with the feds in a system at work and they wanted a password
    minimum 12 characters long
    mix of upper and lower-case letters, numerics and symbols,
    changed monthly
    never written down.
    You can guess how well that went over.

Leave a Reply

When old friends get together, everything else fades to insignificance.

-- War, Famine, Pestilence and Death

    Poll

    Biden as Obama's VP choice is roundly condemned as uninspired or worse. Sarah Palin as McCain's VP choice is...
    View Results

Search

Captain's Logs

The Sites

Syndication

Stats

  • Comments: 2608
  • Pingbacks: 48
  • Trackbacks: 172
  • Comment Spam: 67243
View blog authority