Educause Security Discussion mailing list archives

Re: Please do not change your password


From: David LaPorte <david_laporte () HARVARD EDU>
Date: Wed, 14 Apr 2010 11:10:08 -0400

Not to continue this thread needlessly, but...

The bottom line remains the fact that regulatory bodies mandate it.

These things are mandated because they are truths within the security
industry.  The "majority of attacks are internal" canard is another, IMO
(now the pitchforks are going to come out!)  It's difficult to change an
entrenched mindset without lots of good research and debate.

Current thread: