Security Basics mailing list archives

Re: Password creating Theories


From: "Gaddis, Jeremy L." <jeremy () linuxwiz net>
Date: Tue, 15 Nov 2005 19:41:39 -0500

Jennifer Fountain wrote:
I am currently coming up with a new policy to create root/admin
passwords for windows and linux boxes and would like to know your
thoughts on the methods you use to create them.  Thanks for any input!
Hi Jennifer,

Hopefully you're already accustomed to the practice of using passphrases instead of passwords. What policy you use to create your passphrases isn't as important as ensuring that you have strong, complex passwords. This is even more important as you specifically mention administrator-level passwords for your machines. We usually just pick a random phrase (grab a book, pick a phrase well-used in daily conversations, etc.) and then modify it to meet the complexity requirements that we've set (15 character minimum, uppercase/lowercase/numbers/special characters, etc.).

-j

--
Jeremy L. Gaddis, GCWN
http://www.linuxwiz.net/

"If it's not on fire, it's a software problem."


Current thread: