Educause Security Discussion mailing list archives
Re: (***POSSIBLE SPAM***) Re: [SECURITY] Password Expatriation notification
From: Charles Buchholtz <chip+educause () SEAS UPENN EDU>
Date: Thu, 19 Aug 2010 13:48:35 -0400
On Thu, Aug 19, 2010 at 11:12:17AM -0400, Valdis Kletnieks wrote:
What? Your users can't remember something like 'Bambi+Bippity-boppity-boo'? or "$*%&# security office made me do it" (bonus points for special char use) or "horizontal snow in the fog" (one boy in my Scout troop said he used that for a while, after a memorable climb up a local mountain)?
We allow passwords (minimum 9 chars) and pass-phrases (minimum 16 chars). I've found that some people strongly prefer one and some people strongly prefer the other. I suspect that slow, clumsy typists prefer short passwords because there are fewer chances to mistype a character and it's faster. Fast, accurate typists prefer pass-phrases because they are easier to remember and easier to type. I've watched people who have trouble typing try to enter passwords and pass-phrases. When every character takes 5 seconds to type, a 9 character password is much easier than a 16 character pass-phrase. Charles H. Buchholtz Director of Systems Programming chip () seas upenn edu School of Engineering and Applied Science http://www.seas.upenn.edu/~chip University of Pennsylvania
Current thread:
- Password Expatriation notification, (continued)
- Password Expatriation notification James Farr '05 (Aug 17)
- Re: Password Expatriation notification Ken Connelly (Aug 17)
- Re: Password Expatriation notification Kieper, David (Aug 17)
- Re: Password Expatriation notification Bob Bayn (Aug 17)
- Re: Password Expatriation notification James (Aug 19)
- Re: Password Expatriation notification Ullman, Catherine (Aug 19)
- Re: Password Expatriation notification Mark Monroe (Aug 19)
- Re: (***POSSIBLE SPAM***) Re: [SECURITY] Password Expatriation notification SCHALIP, MICHAEL (Aug 19)
- Re: (***POSSIBLE SPAM***) Re: [SECURITY] Password Expatriation notification Walter Moore (Aug 19)
- Re: (***POSSIBLE SPAM***) Re: [SECURITY] Password Expatriation notification Valdis Kletnieks (Aug 19)
- Re: (***POSSIBLE SPAM***) Re: [SECURITY] Password Expatriation notification Charles Buchholtz (Aug 19)
- Re: (***POSSIBLE SPAM***) Re: [SECURITY] Password Expatriation notification Valdis Kletnieks (Aug 19)
- Re: (***POSSIBLE SPAM***) Re: [SECURITY] Password Expatriation notification Charles Buchholtz (Aug 19)
- Re: (***POSSIBLE SPAM***) Re: [SECURITY] Password Expatriation notification Eric Case (Aug 19)
- Re: (***POSSIBLE SPAM***) Re: [SECURITY] Password Expatriation notification Deke Kassabian (Aug 19)
- Re: Password Expatriation notification Alex Keller (Aug 19)
- Re: Password Expatriation notification SCHALIP, MICHAEL (Aug 19)
- Re: Password Expatriation notification Charles Buchholtz (Aug 19)
- Re: Password Expatriation notification Eric Case (Aug 19)
- Re: Password Expatriation notification charlie derr (Aug 19)
- Re: Password Expatriation notification Eric Case (Aug 19)