Showing posts with label system administration. Show all posts
Showing posts with label system administration. Show all posts

Wednesday, August 10, 2011

More on Passwords

Following my last rant about passwords.  Today's XKCD is right on the money.  However it requires sysadmins to change their silly requirements about having between 6 and 8 letters, with one capitalization and one numeral.  It is clear that the longer a password is the harder it is to guess by a computer.  However if you pick words from around your office (like they do in the movies) you could be susceptible to a really good human guess.

Monday, July 18, 2011

Passwords and Security (cont)

And just like that here we have it
https://browserid.org/
an attempt by Mozilla at unifying your login.  This is exactly whats needed.  One login for all sites, cue Lord of the Rings reference.
There are many sites like banking sites that may not work with this straight away, especially as my bank likes me to change my password every 2 minutes. see previous post.
But with initiatives like this I can see things moving in the right direction.
Google goes a long way towards this, once you are signed in to Gmail you are signed in to all Google products. However that is limiting in that you may want to use something other than Google on the web.

Safe surfing...

Saturday, July 9, 2011

Passwords and Security

I have too many passwords, way too many. Its dangerous I am signed up to many websites, often using my email as a username. I am careful though not to use my the same password for my email as I do for the websites where my username is my emails address. http://bit.ly/rqYTu0 XKCD sums this up quite nicely.  I am a big fan of using google account /facebook /twitter logins for other sites.  This makes perfect sense to me.  I only need one strong password for my gmail account and google with authorize my login to other sites. I really hope many sites pick this up, the internet will become a much safer place, though could force some people to get accounts with services they do not want. The other day I almost signed up to facebook as it was the only way to log in to a site.  I didn't in the end so I never got to use that site, but doubt many people will be in this situation.

This was not the main purpose of this rant.  There are some sites, mainly banking, and also at a previous company where you have to change your passwords every 3 months.  I just think this is totally excessive.  No one takes security seriously at this point.  Every time I have to change my password one of two things happen.  I forget my password and I get locked out or I have to write it down on paper and leave it next to my computer.  Additionally in order to try to remember it I have to pick something easy to remember.  I am not the only one that does this.  That being the case the very process used to create more security is actually creating less security.  So Sysadmins I beg you, stop this there are better ways to increase security.  Insist on very secure passwords that never change or use something like and RSA secureID key.  I admit that they are not always practical measures but at the same time they are better than this pseudo secure method of changing passwords every 3 months.

/rantover