The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Special Forums > Security > IT Security RSS
.
google unix.com



More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
PROBLEM: RSYNC and no user password "secrets" tfort73 AIX 2 09-11-2009 10:31 AM
script that can give login password for "ssh" without involving STDIN gydave Shell Programming and Scripting 2 08-03-2008 07:03 PM
Explain the line "mn_code=`env|grep "..mn"|awk -F"=" '{print $2}'`" Lokesha UNIX for Dummies Questions & Answers 4 12-20-2007 01:52 AM
vi -x <filename>.x "script to decrypt w/out asking password" Boyet UNIX for Dummies Questions & Answers 0 12-20-2006 09:35 PM
user password keeps "unsuccessful attempts" yls177 UNIX for Dummies Questions & Answers 8 04-17-2003 12:58 PM

Reply
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 2 Weeks Ago
iBot's Avatar
iBot iBot is offline
Forum Robot Girl
  
 

Join Date: Sep 2000
Posts: 22,133
What Is The "Best" Password Policy?

I recently overheard a colleague mention that, in hisopinion, the best form of password security for their enterprise is to notenforce monthly or quarterly password changes for their employees.  His reasoning? Enforcing tough passwords andforcing your employees to change them periodically often forces the employees towrite down their passwords (even sometimes posting them on a sticky noteattached to their monitors or desks). This, in his opinion, is more of a security risk than not enforcingperiodic password changes. 

 

At first, I thought that this is one of the craziest ideasthat I had ever heard. This goes against one of the most basic securityprinciples out there…make your passwords tough and change your passwords often.

 

Upon further thought, I decided that the logic behind this ideamakes some sense. Allowing your employees to maintain their passwords for anindefinite amount of time may help to alleviate those people that insist onwriting down their passwords.  This beingsaid, I do not think that this is a viable solution.  Whether or not you force your employees tochange their passwords or not, there will always be those that like to writethem down.  In addition, the risk thatyou would take in allowing indefinite access through a compromised accountwould outweigh the risk of someone reading a password.  




More...
  #2 (permalink)  
Old 2 Weeks Ago
TonyLawrence TonyLawrence is offline
Registered User
  
 

Join Date: Sep 2007
Location: SE Mass
Posts: 133
I suggest people use mnemonics to make passwords - like

"She'll be coming around the mountain when she comes!"

That could be a reminder for

S'bca7wsc!

or

!csw7ab'S

making a simple substitution of 7 for t


It's then relatively safe to leave a sticky with the phrase hanging about.

Of course the phrase should be longer, and can even get more creative - like embedding the password in the first and last column of a 4 line phrase

They are creepy and they're kooky,
mysterious and spooky -
They are all together ooky
The A-d-ams Fam-ily!

The password would be "'T,m-TyT!" (better text would make a better password).
Sponsored Links
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 02:22 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0