StorageMojo





Robin Harris    


Password Misses and Myths

April 22nd, 2006 by Robin Harris in SOHO/SMB, Security & Public Policy

In this post Prof. Eugene Spafford of Purdue talks about security and passwords. There are so many buzzwords and scare-tactic marketing in security that most of the non-technical people I know are reduced to the cyber equivalent of burnt offerings: they subscribe to some (often) dysfunctional security product and then cross their fingers. They don’t have the time and energy to understand where the threats are and how to avoid them (like using Firefox instead of IE, for example). This article briefly delineates the major threat modes for passwords and then offers some thoughtful advice.

I saw an RFP recently for an organization spread over several hundred locations with thousands of employees that required the system to ensure that passwords were changed every month and that no passwords were reused over a seven years. There is no better way to ensure that thousands of passwords are stuck on post-it notes on monitors or under keyboards.

As the good professor concludes:

In summary, forcing periodic password changes given today’s resources is unlikely to significantly reduce the overall threat — unless the password is immediately changed after each use.

Giving users suggestions for selecting passwords that are both memorable to the user and difficult to research, and letting them keep them for a lengthier will result in better security and fewer lost passwords.

2 Responses to ' Password Misses and Myths '

Subscribe to comments with RSS or TrackBack to ' Password Misses and Myths '.


  1. on May 1st, 2006 at 12:59 am

    [...] StorageMojo » Password Misses and Myths: Giving users suggestions for selecting passwords that are both memorable to the user and difficult to research, and letting them keep them for a lengthier [time] will result in better security and fewer lost passwords. [...]

  2. Robin said,

    on May 1st, 2006 at 6:53 am

    Good catch. I need an editor. Want the job? The pay is lousy, but think of all that deathless prose you get to scan.

Leave a reply



StorageMojo RSS Feed January 2009 December 2008 November 2008 October 2008 September 2008 August 2008 July 2008 June 2008 May 2008 April 2008 March 2008 February 2008 January 2008 December 2007 November 2007 October 2007 September 2007 August 2007 July 2007 June 2007 May 2007 April 2007 March 2007 February 2007 January 2007 December 2006 November 2006 October 2006 September 2006 August 2006 July 2006 June 2006 May 2006 April 2006 March 2006 June 2005 April 2005 March 2005 February 2005 January 2005 December 2004 November 2004 October 2004 September 2004