Security Basics mailing list archives

Re: Minimum password requirements


From: _ <nightelf () tartarus uwa edu au>
Date: Sat, 17 Jul 2004 15:52:53 +0800

On Thu, Jul 15, 2004 at 08:26:57AM -0700, Randall M Gunning wrote:
a. Passwords must be changed at least every 90 days.

The only problem I have with this, is that most users will start to pick
easy passwords, or write them down if they're forced to change so
frequently. Personally, I'm all for it but I'm interested in security,
whereas the average user wants to be inconvenienced as little as
possible.

Attachment: _bin
Description:


Current thread: