Educause Security Discussion mailing list archives

Re: Challenge/response questions?


From: Gary Flynn <flynngn () JMU EDU>
Date: Tue, 14 Apr 2009 17:04:32 -0400

Dave Ferguson wrote:
You might take a look at this white paper.

http://www.fishnetsecurity.com/sites/com.fishnetsecurity/downloads/Forgot_Password_Best_Practices_v2.0.pdf

Here are some more resources (though these days I hate providing
PDF links):

Designing Authentication Systems with Challenge Questions
http://hornbeam.cs.ucl.ac.uk/hcs/teaching/GA10/lec5extra/ch08just.pdf

Tips for Avoiding Bad Questions
http://securityps.infosecmedia.com/whitepapers/TipsforAvoidingBadQuestions.pdf

Good Security Questions web site
http://goodsecurityquestions.com



--
Gary Flynn
Security Engineer
James Madison University
www.jmu.edu/computing/security

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature


Current thread: