My Suggestion for the Service Desk
Feb. 23rd, 2012 09:56 amIn today's mail:
My reply:
Subject: Services Account - Password Expiration Date: Thu, 23 Feb 2012 06:00:04 -0600 From: <servicedesk@namelesslargelaboratory.gov> To: <higgins@namelesslargelaboratory.gov> Dear William S Higgins, It is time to renew your NamelessLargeLaboratory Services Account, username higgins. The old password will expire in 6 days, on Feb 28, 2012. Please change your password by going to [URL omitted...]
My reply:
Dear Service Desk: Thank you for the reminder. By the way, February 28th is not six days after February 23rd. Perhaps you might consider acquiring some kind of machine that would help in performing arithmetical calculations. Yours truly, Bill Higgins
no subject
Date: 2012-02-23 06:40 pm (UTC)no subject
Date: 2012-02-24 12:21 am (UTC)no subject
Date: 2012-02-24 01:39 am (UTC)90% of passwords that have to be changed frequently just have a number tacked onto the end which the user just increments each time he's forced to change it. If the bad guys didn't know my old password was foobar17, how is it more secure for me to change it to foobar18 than to leave it foobar17? On the other hand, if they did know it was foobar17, I'm willing to bet that they're going to see if foobar18 works when foobar17 doesn't.
What should security people do instead? Oh, I don't know, maybe reprogram their systems so dictionary attacks won't work? Or audit their systems against social-engineering attacks instead of just technical ones (which includes thinking about why users choose stupid passwords)?
no subject
Date: 2012-02-29 05:58 pm (UTC)no subject
Date: 2012-03-01 05:38 pm (UTC)Very few people are capable of correctly remembering a random string of letters and digits. Choosing such a sequence for the user means you either get more users who forget their passwords, or more people who write them down, which can lead to either someone else finding the written-down password, or to losing the piece of paper where it was written down. Although it is not perfect, letting users choose their own passwords fairly freely and not making them change them until there is an actual reason to is the best compromise available.
no subject
Date: 2012-02-23 09:43 pm (UTC)no subject
Date: 2012-02-24 12:22 am (UTC)no subject
Date: 2012-02-23 09:57 pm (UTC)no subject
Date: 2012-02-24 03:59 am (UTC)Now I'm wondering how they'll handle leap day. :-)
no subject
Date: 2012-02-28 07:36 pm (UTC)