Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. International Change Your Password Day

International Change Your Password Day

Scheduled Pinned Locked Moved The Lounge
swiftquestiondiscussion
70 Posts 29 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J jschell

    Naerling wrote:

    Highest levels of management probably have their childrens name for passwords and never change them..

    Not where I work. They use the same policy as everyone else. Passwords are required to be changed often and they are validated to be strong passwords.

    Naerling wrote:

    I just don't see the need to have a new password every two months. It's not like people are constantly trying to hack your every account (this may have sounded like an invitation, it's not!).

    Err...yes they are. My company tracks penetration attempts and the trivial ones are in the tens if not hundreds every day.

    Naerling wrote:

    And doesn't it take something like a billion years to crack one?

    Huh? A standard dictionary attack with weak password on an unsecured system can crack an account in probably a matter of minutes.

    Naerling wrote:

    I don't have anything to hide.

    What does that have to do with anything?

    Sander RosselS Offline
    Sander RosselS Offline
    Sander Rossel
    wrote on last edited by
    #17

    jschell wrote:

    Huh? A standard dictionary attack with weak password on an unsecured system can crack an account in probably a matter of minutes.

    Was thinking of something else here... Anyway, if a hacker wanted to gain access to my email or computer or whatever and they could crack my password in mere minutes (and even mere hours wouldn't be a problem since I'm not changing my password for at least a couple of days) then what good does it do if I change it after two months? Either I DO notice they cracked my password and change it to something else immediatly (and they could probably crack it again pretty soon) or I don't notice they've cracked it and they got free access until I change my password and they'll have to crack it again (which only takes some minutes/hours). Anyway, once they've got my password and plant some malicious software on my machine changing passwords won't even help me anymore. I think if a hacker really wanted access to my system a password ain't gonna help, at least not a lot. I see a password more as a means to keep non-hackers out of my accounts.

    jschell wrote:

    What does that have to do with anything?

    If I were the queen, president, prime-minister or some rich billionaire I could see why hackers would try to hack me. I'm just a dull average person, nothing to see here move along :) Of course I'm no security specialist, but having the same password for many years for each account does make life easier and if my password was retreived only twice in all my life (still can't figure out how or why) and that doesn't even have to do with changing it regularly then I just keep on keeping the same old password until someone finds out what it is again (which can still take many years) :)

    It's an OO world.

    public class Naerling : Lazy<Person>{
    public void DoWork(){ throw new NotImplementedException(); }
    }

    1 Reply Last reply
    0
    • G GenJerDan

      New polcy at work. Bigass password using uppers and lowers and numbers and "special". Not and/or...and. And can't be one used during the the previous 24 passwords. And has to be changed every 90 days. (That's what? 6 years?) I think the not-used-before nonsense came from secure commo. The bad guys could/would save all the datastreams you transmitted and bounce them against any passwords they captured or broke, hoping one would match eventually. (That's why old keys were a much bigger deal to lose than new ones.) However, I don't think any hackers out there are packet-capturing and saving forever in hopes we reuse a password someday. Certainly not on our freaking intranet. ;P

      No dogs or cats are in the classroom. My Mu[sic] My Films My Windows Programs, etc.

      Sander RosselS Offline
      Sander RosselS Offline
      Sander Rossel
      wrote on last edited by
      #18

      So you now got memo's with people's passwords who can't remember them all around the office? :)

      It's an OO world.

      public class Naerling : Lazy<Person>{
      public void DoWork(){ throw new NotImplementedException(); }
      }

      D 1 Reply Last reply
      0
      • H Henry Minute

        ICYPD[^]. It seems that someone else is trying to start an International Change Your Password Day - February 1st. A swift search on change password day reveals at least 4 other attempts at starting national/international days, on the first page of results. This would indicate that the idea of having a special day for it has not caught on. What do you think? Is it the idea of a special day for it that isn't popular or just a lack of interest (lack of comprehension for the need) to change them.

        Henry Minute Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.” I wouldn't let CG touch my Abacus! When you're wrestling a gorilla, you don't stop when you're tired, you stop when the gorilla is. Cogito ergo thumb - Sucking my thumb helps me to think.

        L Offline
        L Offline
        Lost User
        wrote on last edited by
        #19

        It's probably also International Write Your New Password Down Day

        H 1 Reply Last reply
        0
        • L Lost User

          It's probably also International Write Your New Password Down Day

          H Offline
          H Offline
          Henry Minute
          wrote on last edited by
          #20

          How true!

          Henry Minute Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.” I wouldn't let CG touch my Abacus! When you're wrestling a gorilla, you don't stop when you're tired, you stop when the gorilla is. Cogito ergo thumb - Sucking my thumb helps me to think.

          1 Reply Last reply
          0
          • Sander RosselS Sander Rossel

            Henry Minute wrote:

            making sure that the highest levels of management knew why

            Highest levels of management probably have their childrens name for passwords and never change them... I don't even think they'd know what you're talking about :laugh: I just don't see the need to have a new password every two months. It's not like people are constantly trying to hack your every account (this may have sounded like an invitation, it's not!). It's just very inconvenient for me, remembering all those passwords (and I have forgotten a few)... Besides, what could evil-doers do with my old password that they couldn't do with my new one? And doesn't it take something like a billion years to crack one? My guess is that if hackers get my password they don't need two months to get it and so if they do I'm always to late with changing it, wether I change it once a year or once a month... Guess I'm just not very paranoid or I don't have anything to hide. I must say someone gained access to my MSN account and to my World of Warcraft account once (two seperate incidents with I think very different passwords). Very nasty business. Changed my password after both incidents. In case of WoW I had my account about three months and I'm very sure changing my password after two months wouldn't have made a difference. I installed a keyscrambler after that :)

            It's an OO world.

            public class Naerling : Lazy<Person>{
            public void DoWork(){ throw new NotImplementedException(); }
            }

            H Offline
            H Offline
            Henry Minute
            wrote on last edited by
            #21

            Naerling wrote:

            I just don't see the need to have a new password every two months.

            For your private (i.e. domestic) logins, your choice. For work related matters if the company has a policy for these sort of things then conformance is probably part of your contract of employment. Stamping your foot and screaming "shan't" or even holding your breath until you turn blue just don't cut it. :) The fact that you don't see the need has no bearing whatever. There are in all probability many company policies that you don't see the need for but the fact remains that it ain't up to you. As I said before, if I was the admin you'd be gone.

            Henry Minute Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.” I wouldn't let CG touch my Abacus! When you're wrestling a gorilla, you don't stop when you're tired, you stop when the gorilla is. Cogito ergo thumb - Sucking my thumb helps me to think.

            Sander RosselS 1 Reply Last reply
            0
            • H Henry Minute

              Naerling wrote:

              I just don't see the need to have a new password every two months.

              For your private (i.e. domestic) logins, your choice. For work related matters if the company has a policy for these sort of things then conformance is probably part of your contract of employment. Stamping your foot and screaming "shan't" or even holding your breath until you turn blue just don't cut it. :) The fact that you don't see the need has no bearing whatever. There are in all probability many company policies that you don't see the need for but the fact remains that it ain't up to you. As I said before, if I was the admin you'd be gone.

              Henry Minute Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.” I wouldn't let CG touch my Abacus! When you're wrestling a gorilla, you don't stop when you're tired, you stop when the gorilla is. Cogito ergo thumb - Sucking my thumb helps me to think.

              Sander RosselS Offline
              Sander RosselS Offline
              Sander Rossel
              wrote on last edited by
              #22

              You're absolutely right. The boss makes the rules, but who am I to not question them? ;) In this case I was completely surprised by the fact that I had to change my password, no one told me and it was a new policy. So I went to my boss and told him what I told you, that I'd have to write it down which is even more unsecure. Besides we're a small company with only three or four employees at the time in a small village with no competition. Changing passwords every two months is just a pain in the arse and my boss agreed rather quickly. At a bigger company I would probably abide by the rules (although not before raising some hell about it, and only if I didn't agree to it earlier of course). I don't simply do anything because someone tells me to, even if it's my boss. I'm not all bad though. If I see something in the company or our product could be improved I come up with idea's and share them with my employer who can then take action or not (and my input is appreciated, since I do have good idea's at times). So the whole smartass attitude goes go two ways, sometimes in favour, and sometimes not in favour, for my employers (in contrast to colleagues who 'just' do their work) :) You wouldn't want only employees like me, but I think every company needs a few ;)

              It's an OO world.

              public class Naerling : Lazy<Person>{
              public void DoWork(){ throw new NotImplementedException(); }
              }

              R 1 Reply Last reply
              0
              • Sander RosselS Sander Rossel

                You're absolutely right. The boss makes the rules, but who am I to not question them? ;) In this case I was completely surprised by the fact that I had to change my password, no one told me and it was a new policy. So I went to my boss and told him what I told you, that I'd have to write it down which is even more unsecure. Besides we're a small company with only three or four employees at the time in a small village with no competition. Changing passwords every two months is just a pain in the arse and my boss agreed rather quickly. At a bigger company I would probably abide by the rules (although not before raising some hell about it, and only if I didn't agree to it earlier of course). I don't simply do anything because someone tells me to, even if it's my boss. I'm not all bad though. If I see something in the company or our product could be improved I come up with idea's and share them with my employer who can then take action or not (and my input is appreciated, since I do have good idea's at times). So the whole smartass attitude goes go two ways, sometimes in favour, and sometimes not in favour, for my employers (in contrast to colleagues who 'just' do their work) :) You wouldn't want only employees like me, but I think every company needs a few ;)

                It's an OO world.

                public class Naerling : Lazy<Person>{
                public void DoWork(){ throw new NotImplementedException(); }
                }

                R Offline
                R Offline
                Rob Grainger
                wrote on last edited by
                #23

                Wow, I'm speechless. I hope you're proud of the fact that this childish attitude has probably made your company fail to comply with data protection law in the country you are based in. Which rock have you been hiding to be so unaware of security issues over the last few years? I'm with Henry here, with that attitude, either you'd go or me. If it was me, I'd then sue for constructive dismissal.

                Sander RosselS C S 3 Replies Last reply
                0
                • H Henry Minute

                  ICYPD[^]. It seems that someone else is trying to start an International Change Your Password Day - February 1st. A swift search on change password day reveals at least 4 other attempts at starting national/international days, on the first page of results. This would indicate that the idea of having a special day for it has not caught on. What do you think? Is it the idea of a special day for it that isn't popular or just a lack of interest (lack of comprehension for the need) to change them.

                  Henry Minute Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.” I wouldn't let CG touch my Abacus! When you're wrestling a gorilla, you don't stop when you're tired, you stop when the gorilla is. Cogito ergo thumb - Sucking my thumb helps me to think.

                  A Offline
                  A Offline
                  AdamEcc
                  wrote on last edited by
                  #24

                  I would have thought that having a specific day for everyone to change their passwords would be more of a security risk. Surely the chance of any given password being being intercepted and / or hacked is higher if the probability of any given data transfer being a password is above average?

                  1 Reply Last reply
                  0
                  • H Henry Minute

                    ICYPD[^]. It seems that someone else is trying to start an International Change Your Password Day - February 1st. A swift search on change password day reveals at least 4 other attempts at starting national/international days, on the first page of results. This would indicate that the idea of having a special day for it has not caught on. What do you think? Is it the idea of a special day for it that isn't popular or just a lack of interest (lack of comprehension for the need) to change them.

                    Henry Minute Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.” I wouldn't let CG touch my Abacus! When you're wrestling a gorilla, you don't stop when you're tired, you stop when the gorilla is. Cogito ergo thumb - Sucking my thumb helps me to think.

                    G Offline
                    G Offline
                    G Tek
                    wrote on last edited by
                    #25

                    I think Feb 29th would be a great ICYPD! :doh:

                    1 Reply Last reply
                    0
                    • A AspDotNetDev

                      GenJerDan wrote:

                      And can't be one used during the the previous 24 passwords. And has to be changed every 90 days. (That's what? 6 years?)

                      Just change your password 24 times in a row:

                      Password^1
                      Password^2
                      Password^3
                      ...
                      Password^24
                      RealPassword$1

                      :rolleyes:

                      Thou mewling ill-breeding pignut!

                      S Offline
                      S Offline
                      Stefan_Lang
                      wrote on last edited by
                      #26

                      On top of the above rules, our SAP system also requires that a new password is signifcantly different from all the previous ones. Of course, after three failed tries on logging in you're locked out as well, so the whole pain you're going through to create the illusion of a strong password is totally in vain... X|

                      1 Reply Last reply
                      0
                      • A AspDotNetDev

                        Note to self: monitor HTTP and SMTP traffic on February 1st to gather lots and lots of new passwords.

                        Thou mewling ill-breeding pignut!

                        S Offline
                        S Offline
                        Stefan_Lang
                        wrote on last edited by
                        #27

                        I've considered that too: hackers would rejoice and focus their efforts on that particular day - no better cance to get some real valuable data, and it likely won't be changed for a year! Now they can even put a 'best before end' stamp on it before selling them! At least in theory - I have no idea if hackers could really gain a benefit from such knowledge, but I suspect on certain types of password systems it might in fact be possible. For that reason alone the idea sounds flawed.

                        M 1 Reply Last reply
                        0
                        • H Henry Minute

                          ICYPD[^]. It seems that someone else is trying to start an International Change Your Password Day - February 1st. A swift search on change password day reveals at least 4 other attempts at starting national/international days, on the first page of results. This would indicate that the idea of having a special day for it has not caught on. What do you think? Is it the idea of a special day for it that isn't popular or just a lack of interest (lack of comprehension for the need) to change them.

                          Henry Minute Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.” I wouldn't let CG touch my Abacus! When you're wrestling a gorilla, you don't stop when you're tired, you stop when the gorilla is. Cogito ergo thumb - Sucking my thumb helps me to think.

                          S Offline
                          S Offline
                          Stefan_Lang
                          wrote on last edited by
                          #28

                          I'd prefer a ICYPSD - 'international change your password system day'. Current password systems are so flawed, it's not funny anymore. All they achive is make it harder for users to remember their passwords, and easier for computers to guess, because they (the PW systems) effectively force them (i. e. the users) to either write them (the passwords) down, or choose ones that can be easily broken, or both. To add insult to injury, many of those stupid systems not only force you to repeatedly choose new, difficult to remember passwords, but they'll also lock you out after three unsuccessful tries. Why do we have to jump through hoops in an effort to create the illusion* of a safe password, when no password cracking system ever gets a reasonable chance to try them out? Even if a hacker considered trying to log into a million accounts, it shouldn't take more than a few hundred failed tries for the system to realize there is something seriously amiss. It definitely should not require any of those other stupid enforced rules, except PW length. *: Why I said 'illusion': http://xkcd.com/936/[^]

                          1 Reply Last reply
                          0
                          • R Rob Graham

                            what's a password?

                            "People who bite the hand that feeds them usually lick the boot that kicks them." Eric Hoffer "The failure mode of 'clever' is 'asshole'" John Scalzi "Only buzzards feed on their friends" Patrick Dorinson

                            P Offline
                            P Offline
                            Paulo_JCG
                            wrote on last edited by
                            #29

                            Correct me if i am wrong. A pass is what you have to go on the bus... a word is a 2 byte integer.... so i think it must be a 2 byte integer to go on the bus I don't like bus

                            Paulo Gomes Over and Out :D

                            1 Reply Last reply
                            0
                            • S Stefan_Lang

                              I've considered that too: hackers would rejoice and focus their efforts on that particular day - no better cance to get some real valuable data, and it likely won't be changed for a year! Now they can even put a 'best before end' stamp on it before selling them! At least in theory - I have no idea if hackers could really gain a benefit from such knowledge, but I suspect on certain types of password systems it might in fact be possible. For that reason alone the idea sounds flawed.

                              M Offline
                              M Offline
                              Marbry Hardin
                              wrote on last edited by
                              #30

                              If you put onerous password requirements on people, you'll just increase the incidence of people simply writing them down. Users that have trouble typing normal text aren't going to be keen to have to type in some long bit of gibberish every time they have to login.

                              S 1 Reply Last reply
                              0
                              • H Henry Minute

                                ICYPD[^]. It seems that someone else is trying to start an International Change Your Password Day - February 1st. A swift search on change password day reveals at least 4 other attempts at starting national/international days, on the first page of results. This would indicate that the idea of having a special day for it has not caught on. What do you think? Is it the idea of a special day for it that isn't popular or just a lack of interest (lack of comprehension for the need) to change them.

                                Henry Minute Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.” I wouldn't let CG touch my Abacus! When you're wrestling a gorilla, you don't stop when you're tired, you stop when the gorilla is. Cogito ergo thumb - Sucking my thumb helps me to think.

                                J Offline
                                J Offline
                                jsc42
                                wrote on last edited by
                                #31

                                Using the same password is OK until you go to one of those stupid blog sites that require you to use your FaceBook / OpenID / LiveID / GoogleMail credentials just to make a comment when you have no idea how secure the site is. I thought that I was fairly safe until the day I got an email that was addressed to 'Dear ********' (where ******** was the password that I had used all over the place). If you're going to skim passwords and send phishing letters, you could at least have the sense to not use the password as the recipient's name - that is a dead giveaway. Besides, when company's insist on complicated passwords (e.g. at least one capital letter, one lowercase letter, one digit, one 'special char), what do people do? They capitalise the first letter and append 1! to the end. No more secure than before. We have an application that decided to double the password length. What did everyone do? Wrote the old password twice (except for one person who had a 1/2 length password that he was already writing twice - he just wrote that 4 times). And when passwords expire at different frequencies, you dedicate one day every min password change frequency to update the lot. And if this is monthly, you can virtually guarantee that the month will be encoded in the password somewhere. Why do we still have passwords? They were debunked in the 1960s as insecure. They are no better than the old miltary "Halt! Who goes there? Friend or Foe?" as long as you answer "Friend" you are in.

                                1 Reply Last reply
                                0
                                • M Marc Clifton

                                  Henry Minute wrote:

                                  What do you think?

                                  I think it should be Feb. 29th. ;) Marc

                                  My Blog
                                  An Agile walk on the wild side with Relationship Oriented Programming
                                  Melody's Amazon Herb Site

                                  J Offline
                                  J Offline
                                  jsc42
                                  wrote on last edited by
                                  #32

                                  Marc Clifton wrote:

                                  I think it should be Feb. 29th

                                  Agreed - but only on century years (so, after 2000, the next password change day will be Feb 29th 2400). This will give me enough time to memorise my password and to get it right before it needs changing again.

                                  1 Reply Last reply
                                  0
                                  • H Henry Minute

                                    ICYPD[^]. It seems that someone else is trying to start an International Change Your Password Day - February 1st. A swift search on change password day reveals at least 4 other attempts at starting national/international days, on the first page of results. This would indicate that the idea of having a special day for it has not caught on. What do you think? Is it the idea of a special day for it that isn't popular or just a lack of interest (lack of comprehension for the need) to change them.

                                    Henry Minute Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.” I wouldn't let CG touch my Abacus! When you're wrestling a gorilla, you don't stop when you're tired, you stop when the gorilla is. Cogito ergo thumb - Sucking my thumb helps me to think.

                                    P Offline
                                    P Offline
                                    PinballWizard
                                    wrote on last edited by
                                    #33

                                    on a daily basis it will exercise your brain's right hemisphere

                                    --------- Antonio

                                    1 Reply Last reply
                                    0
                                    • Sander RosselS Sander Rossel

                                      So you now got memo's with people's passwords who can't remember them all around the office? :)

                                      It's an OO world.

                                      public class Naerling : Lazy<Person>{
                                      public void DoWork(){ throw new NotImplementedException(); }
                                      }

                                      D Offline
                                      D Offline
                                      Dominic Amann
                                      wrote on last edited by
                                      #34

                                      In a slight irony, I had to change my password through the "lost password" procedure to login and post this (long time lurker). The problem with not changing your password, and having the same password (or two) in most places is profound. For example - if you had the same password for WoW and your online banking, I am sure even you can see how it would be an issue. That is just an obvious example. You use the fact that a simple dictionary password can be cracked in minutes as an excuse to not change it. You should have quite complex passwords that would in fact take months if not years to crack. The problem with this, of course, is that it is inconvenient. I would argue that there are fairly simple ways to create complex, yet memorable passwords. One I prefer is to take simple 3 word phrases (such as Crick Crack Monkey), and using letters from these words, interspaced with numbers and/or special characters, depending on the length and complexity requirements of the system. For example, Cr1Cr2Mo3 is one example, or Cr!1Cr@2Mo as another. All one has to do is remember the basic formula, and the three word phrase. Of course using a formula reduces the word-space the cracker has to search, but it is better than whole or half words or names typically used. Another advantage is that you can use the source of your phrase as your password reminder (for my Crick Crack Monkey example it would be Paul Keanes Douglas - the author of the poem). For a Beatles song such as "Every Little Things", the clue could be "Six Beatles for Sale" (the album the song came on, and track number). Now having said all this, I believe that passwords are still inadequate and inconvenient. We need a stronger, two way security system. Google's new challenge and answer system goes a long way towards this. Their system has a password, and then sends another token to you (via cellphone), which you must key in. Face recognition is also improving (and can be used on some phones). Things are also moving to single-sign-in, so you can connect to many other sites using either your facebook, twitter or google (or other) accounts. This is either more secure (if you use a strong password and secure system), because you will take the trouble to maintain a good password, or far far less - if you use a crummy password on your primary login.

                                      1 Reply Last reply
                                      0
                                      • Sander RosselS Sander Rossel

                                        I can barely remember my one password with about three flavours that I use for about every account I have anywhere... I'm actually trying to change any password that doesn't match my most used one to my most used one so I don't need 10 login attempts to log in. First thing I did when company policy forced me to change my password was raise some hell, because getting a new password creates the need to write it down which is much less secure than keeping the same password for just a bit longer. I got to keep my password :)

                                        It's an OO world.

                                        public class Naerling : Lazy<Person>{
                                        public void DoWork(){ throw new NotImplementedException(); }
                                        }

                                        B Offline
                                        B Offline
                                        BrainiacV
                                        wrote on last edited by
                                        #35

                                        That's why I put all my passwords into my Gateway 2000 programmable keyboard ;P While that might not sound secure, each key can have ALT-CTRL-SHIFT prefixes, so you'd have to figure out which keys to press before you lock yourself out from the account. Not as easy as WarGames' printed list hidden somewhere or the password on the blackboard at school. But admittedly not too far behind. But the ultimate advantage is that I don't have to remember the passwords at all. :laugh:

                                        Psychosis at 10 Film at 11 Those who do not remember the past, are doomed to repeat it. Those who do not remember the past, cannot build upon it.

                                        Sander RosselS 1 Reply Last reply
                                        0
                                        • H Henry Minute

                                          Naerling wrote:

                                          I got to keep my password

                                          You wouldn't have if you worked anywhere that I was Systems Admin. If you point blank refused, either you'd have to go, or I would voluntarily go, making sure that the highest levels of management knew why. Sorry, but in this case it ain't big and it certainly ain't clever.

                                          Henry Minute Girl: (staring) "Why do you need an icy cucumber?" “I want to report a fraud. The government is lying to us all.” I wouldn't let CG touch my Abacus! When you're wrestling a gorilla, you don't stop when you're tired, you stop when the gorilla is. Cogito ergo thumb - Sucking my thumb helps me to think.

                                          B Offline
                                          B Offline
                                          Bruce Patin
                                          wrote on last edited by
                                          #36

                                          Changing your password without a good reason is a mindless practice that has been passed down long ago and is no longer valid. It used to be that a hacker could download a password file and take days to decrypt it. If you changed your password during that time, you would have saved yourself some distress, but only if you changed it during that time, a window of a now unlikely opportunity that has gotten so small that regularly changing your password no longer helps that situation. Another reason to change your password is if you have given it to anyone or suspect that someone has read the note that you had to put it on, because some smart system admin has made unreasonable rules that you can't follow without writing it down. In that case, you should change your password right away, not wait for the scheduled time period to do it. There are only two rules that really apply to users these days: 1. Don't give it to anyone. 2. Make it a long multiple word phrase (more than 20 characters) that is easy for you to remember. And there are two rules for system administrators: 1. Never store the password in clear text or transmit it over email. 2. Allow long passwords and don't force arbitrary rules and restrictions about it.

                                          H Sander RosselS S 3 Replies Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups