Security Basics mailing list archives

Re: Re[2]: Suggested "safe" password length


From: "Chris Berry" <compjma () hotmail com>
Date: Fri, 21 Nov 2003 13:00:51 -0800

From: Vishal <dhrakol () myrealbox com>
Everyone gets complacent, lazy or forgetful once in a while, no matter the
consequences. Or I might simply have my mind on something else.

>> Another good option is to maintain a PGP encrypted text file of passwords.
>> That way the user only needs to remember one PGP passphrase.

ARM> Why is this any different than "constantly having to rifle through [your
ARM> wallet] for a password list"?

Because you can memorize that one passphrase. There isn't the chance of
leaving it lying around like a wallet.

Of course, if your users are like mine, they then promptly forget their password file passphrase and call you about it all the time. Still that seems to work better than the other things we've tried. We use PasswordSafe

http://sourceforge.net/projects/passwordsafe/

Chris Berry
compjma () hotmail com
Systems Administrator
JM Associates

"Beware of Windows. IE...Outlook...Office...The dark side of the OS are they." "Easily does it flow, quick to setup. If once you start down the dark path, forever will it dominate your destiny."
"Consume you it will, as it did Ballmer and Gates."
"Is Windows stronger than Linux?"
"No!....Quicker, easier, more seductive."
"But how am I to know the good side from the bad?"
"You will KNOW.  When you are root, at the command line, knowledgeable."

_________________________________________________________________
online games and music with a high-speed Internet connection! Prices start at less than $1 a day average. https://broadband.msn.com (Prices may vary by service area.)


---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: