Security Basics mailing list archives

Fwd: Password alternatives


From: Kurt Buff <kurt.buff () gmail com>
Date: Mon, 29 Mar 2010 15:53:03 -0700

On Fri, Mar 26, 2010 at 10:18, WALI <hkhasgiwale () gmail com> wrote:
Hi guys

The recent attempt to roll out password complexity within our AD domain has
not been well recieved by higher / executive management. These guys have a
habit of sharing their passwords with their PAs and secretaries and now they
are cribbing when they need to change their password every 90 days.

What are best and most workable alternatives? Biometrics, RSA tokens? Any
thing else which you guys have implemented with relative ease?

Pls advise!

What resources are the PA and secretaries being allowed to see/use?

If it's standard stuff, such as files/directories, and perhaps
Exchange/Outlook email and calendars, setting up groups for the former
and delegation for the latter will solve this problem.

Also, I'd offer a compromise - longer passwords (passphrases, really,
and the education to know that a complete sentence that's easy to type
is acceptable), with the requirement to change only once per year. I'd
think that a 18+ character sentence (My dog's name is Rin Tin Tin.)
with spaces and punctuation is easier to remember and type than
*$sdADx333.

Kurt

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: