Security Basics mailing list archives

Re: Password Storage


From: "Rob klein Gunnewiek" <rob.kleingunnewiek () gmail com>
Date: Wed, 2 Aug 2006 10:59:31 +0200

On 8/1/06, Doug W <dougiegee () hotmail com> wrote:
Hi Everyone

What do people generally do in the case of password storage?  For example, I
strongly believe that storing passwords in documents is a terrible idea as I
am sure you would agree.


Store them in encrypted format. Even better it is when the employees
carry PDA's. For example, I have a Palm PDA and use the program
"Strip" to store all my passwords strongly encrypted with 256-bit AES.
If I lose the PDA, still my passwords will be safe.

Never store them in plain text. You can better have a post-it on your
monitor than having it stored in clear text on your PC IMO.

--
Met vriendelijke groet,
Rob klein Gunnewiek

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: