Password policy

After my experiences today I’m reconsidering the way I look at password policies. I had to go around and install the new drivers for that Canon copier/printer today on about 15 machines. The install involved installing the Canon LPR port, installing the print driver, restarting, and then entering the Department ID information for the print job accounting functions. So I would sit down at a PC, run the installers, and ask the user to enter their password when the PC restarted. Most of them would just tell me what the password was instead of getting up from where they had settled to type it. A couple of these folks had to get up and type it in because they couldn’t remember it. Typing it in had become such a routine that they couldn’t tell you what it was, but they could type it. That told me two things:

1) I’m obviously not making them expire often enough. (I already knew that, but since there are no direct internet-facing PC’s, everything sits behind another company’s whole network infrastructure, and it’s a small enough environment that I can keep a pretty close eye on things, I have been more lax than I would be in any other situation. I don’t make them change it as often as most of you probably do with your users.)

2. You could never use social engineering to get these people’s passwords. They can’t tell you what they are! Maybe there’s something to be said for letting people type in the same password for long periods of time, making it such a routine that they can’t give it to anyone else. 🙂

Similar Posts

  • Intellisync

    In the comments to a previous post I mentioned wanting to have a way for my wife to be able to see my calendar, which I normally keep in Outlook on my laptop. I knew I could publish to the web, but since I only want her to see it that would require setting up…

  • More problems

    Yeah I had to take the referrer script down again. At least now I know why the results keep stretching the table width to ridiculous proportions. If a website does not specify a page name, the script prints out the entire URL. Since there’s no space in the URL the table doesn’t try to wrap…

  • Random news

    Bits of news to bookmark for myself: Messenger Plus bundling spyware in it’s install. Microsoft introducing security certifications. -Like there aren’t enough certs to choose from? 🙂 MS looking to simplify patch management. Dell drops prices on Axims -The Axim is a really good PocketPC for the price and the price keeps getting better. Looks…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)