Password policy

After my experiences today I’m reconsidering the way I look at password policies. I had to go around and install the new drivers for that Canon copier/printer today on about 15 machines. The install involved installing the Canon LPR port, installing the print driver, restarting, and then entering the Department ID information for the print job accounting functions. So I would sit down at a PC, run the installers, and ask the user to enter their password when the PC restarted. Most of them would just tell me what the password was instead of getting up from where they had settled to type it. A couple of these folks had to get up and type it in because they couldn’t remember it. Typing it in had become such a routine that they couldn’t tell you what it was, but they could type it. That told me two things:

1) I’m obviously not making them expire often enough. (I already knew that, but since there are no direct internet-facing PC’s, everything sits behind another company’s whole network infrastructure, and it’s a small enough environment that I can keep a pretty close eye on things, I have been more lax than I would be in any other situation. I don’t make them change it as often as most of you probably do with your users.)

2. You could never use social engineering to get these people’s passwords. They can’t tell you what they are! Maybe there’s something to be said for letting people type in the same password for long periods of time, making it such a routine that they can’t give it to anyone else. 🙂

Similar Posts

  • Holiday Party

    We survived my office holiday party last night. As they say back in my old neighborhood, there was no gun play so it was a good party! (No that’s not a trivial matter, there is quite a bit of animosity between various people in my office. *L*) Seriously though, the food was alright, (although Angela…

  • To judge or not to judge?

    You’ll of course remember a few days ago when Chris posted his Blogger’s Manifesto, right? Well now David Weinberger has parodied that into the Real Blogger’s Manifesto, which is pretty funny. Then, Mike Sanders kicked in with his question about the original manifesto; how Chris can routinely judge others while asking not to be judged…

  • Note to someone

    Scoble pointed to this story about the possibility of a Pocket PC pricewar just in time for Christmas. Given all the discussion we’ve had around here concerning PocketPC and Palm, it’s probably worth noting to someone planning to buy me a Christmas gift. 🙂 By the way, I think the deciding factor between PocketPc and…

  • Things I’ll miss

    As a follow up to yesterday’s post, here’s a handful of things I’m going to miss about working in small business IT: Autonomy: I’ve pretty much been able to do whatever I want, however I want, within reason obviously. I think Firefox is a better browser, I install it on my PC. I think the…

  • Completely unacceptable

    That was what I thought when I saw this post about McAfee’s screw up with the definition files they released Friday morning. It’s completely unacceptable that those def files got released to the public, and that for five hours, the folks who were doing everything we tell them to do in terms of keeping udated,…

  • Waiting and watching

    So XP SP2 has released to manufacturing. I’m going to be keeping a careful eye on reactions, issues, breakage, etc. for the next few days. Hopefully after I’ve had a few days to see what everyone else is experiencing with this, I’ll go get it myself and start testing on our network. Luckily there are…

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)