Experiences and Lessons learned from my position as CTO in a small tech company in Israel. Follow me on twitter @ctoisrael. Comment if you want help with something that I have written about.
Showing posts with label passwords. Show all posts
Showing posts with label passwords. Show all posts
Wednesday, August 10, 2011
More on Passwords
Following my last rant about passwords. Today's XKCD is right on the money. However it requires sysadmins to change their silly requirements about having between 6 and 8 letters, with one capitalization and one numeral. It is clear that the longer a password is the harder it is to guess by a computer. However if you pick words from around your office (like they do in the movies) you could be susceptible to a really good human guess.
Labels:
passwords,
security,
sysadmin,
system administration
Monday, July 18, 2011
Passwords and Security (cont)
And just like that here we have it
https://browserid.org/
an attempt by Mozilla at unifying your login. This is exactly whats needed. One login for all sites, cue Lord of the Rings reference.
There are many sites like banking sites that may not work with this straight away, especially as my bank likes me to change my password every 2 minutes. see previous post.
But with initiatives like this I can see things moving in the right direction.
Google goes a long way towards this, once you are signed in to Gmail you are signed in to all Google products. However that is limiting in that you may want to use something other than Google on the web.
Safe surfing...
https://browserid.org/
an attempt by Mozilla at unifying your login. This is exactly whats needed. One login for all sites, cue Lord of the Rings reference.
There are many sites like banking sites that may not work with this straight away, especially as my bank likes me to change my password every 2 minutes. see previous post.
But with initiatives like this I can see things moving in the right direction.
Google goes a long way towards this, once you are signed in to Gmail you are signed in to all Google products. However that is limiting in that you may want to use something other than Google on the web.
Safe surfing...
Labels:
passwords,
security,
sysadmin,
system administration
Saturday, July 9, 2011
Passwords and Security
I have too many passwords, way too many. Its dangerous I am signed up to many websites, often using my email as a username. I am careful though not to use my the same password for my email as I do for the websites where my username is my emails address. http://bit.ly/rqYTu0 XKCD sums this up quite nicely. I am a big fan of using google account /facebook /twitter logins for other sites. This makes perfect sense to me. I only need one strong password for my gmail account and google with authorize my login to other sites. I really hope many sites pick this up, the internet will become a much safer place, though could force some people to get accounts with services they do not want. The other day I almost signed up to facebook as it was the only way to log in to a site. I didn't in the end so I never got to use that site, but doubt many people will be in this situation.
This was not the main purpose of this rant. There are some sites, mainly banking, and also at a previous company where you have to change your passwords every 3 months. I just think this is totally excessive. No one takes security seriously at this point. Every time I have to change my password one of two things happen. I forget my password and I get locked out or I have to write it down on paper and leave it next to my computer. Additionally in order to try to remember it I have to pick something easy to remember. I am not the only one that does this. That being the case the very process used to create more security is actually creating less security. So Sysadmins I beg you, stop this there are better ways to increase security. Insist on very secure passwords that never change or use something like and RSA secureID key. I admit that they are not always practical measures but at the same time they are better than this pseudo secure method of changing passwords every 3 months.
/rantover
This was not the main purpose of this rant. There are some sites, mainly banking, and also at a previous company where you have to change your passwords every 3 months. I just think this is totally excessive. No one takes security seriously at this point. Every time I have to change my password one of two things happen. I forget my password and I get locked out or I have to write it down on paper and leave it next to my computer. Additionally in order to try to remember it I have to pick something easy to remember. I am not the only one that does this. That being the case the very process used to create more security is actually creating less security. So Sysadmins I beg you, stop this there are better ways to increase security. Insist on very secure passwords that never change or use something like and RSA secureID key. I admit that they are not always practical measures but at the same time they are better than this pseudo secure method of changing passwords every 3 months.
/rantover
Labels:
passwords,
security,
sysadmin,
system administration
Subscribe to:
Posts (Atom)