Educause Security Discussion mailing list archives

Re: Password hints


From: Wayne Samardzich <Samardzi () CALUMET PURDUE EDU>
Date: Sun, 14 Dec 2008 13:36:53 -0600

Only allow a certain set of questions.  Drop down lists with a dozen or so questions. 

----- Original Message -----
From: The EDUCAUSE Security Constituent Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU>
To: SECURITY () LISTSERV EDUCAUSE EDU <SECURITY () LISTSERV EDUCAUSE EDU>
Sent: Sun Dec 14 12:54:55 2008
Subject: Re: [SECURITY] Password hints


On 13/12/2008, at 12:57 PM, Brian Kaye wrote:

Why not allow them to create their own challenge question with some
appropriate scan of the question and answer?

the later is the difficult bit.   How do you stop people including the  
password in the question?

Russell

Current thread: