UGN Security Forums
My ProfileMember DirectoryLogin
Search our ForumsView our FAQView our Site Rules
View our CalendarView our Active TopicsGo to our Main Page

UGN Security Store

Network Sites UGN Security, The GoNix Initiative, Elite Web Gamers, Back of the Web, EveryDay Helper, VNC Web Design & Development
Sponsored Links
Latest Postings
by Herbert_Sherbert
09/07/15 10:34 AM
Latest Reviews
Topic Options
Rate This Topic
#35277 - 05/23/05 04:16 PM Security guru backs writing down passwords
Digital Geek Offline
UGN Super Poster

Registered: 09/18/02
Posts: 553
Loc: Cluj-Napoca, Romania
Companies should not ban employees from writing down their passwords because it forces users to use the same weak term on many systems, according to a Microsoft security guru.

Speaking on the opening day of the AusCERT conference on Australia's Gold Coast, Jesper Johansson, senior programme manager for security policy at Microsoft, said the security industry had been giving out the wrong advice to users by telling them not to write down their passwords.

"How many have password policy that says 'under penalty of death you shall not write down your password'?" asked Johansson, to which the majority of delegates raised their hands in agreement. "I claim that is absolutely wrong. I claim that password policy should say you should write down your password. I have 68 different passwords. If I am not allowed to write any of them down, guess what I am going to do? I am going to use the same password on every one of them," he said.

According to Johansson, use of the same password reduces overall security.

"Since not all systems allow good passwords I am going to pick a really crappy one, use it everywhere and never change it. If I write them down and then protect the piece of paper — or whatever it is I wrote them down on — there is nothing wrong with that. That allows us to remember more passwords and better passwords," said Johansson.

Johansson said the security industry had been giving out the wrong advice about passwords for 20 years.

Delegates at the conference agreed that Johansson's advice made sense. However, they did not think it was practical.

One IT administrator from an international entertainment company, who requested anonymity, said that despite it being strict company policy to not make a note of passwords, he collated his personal passwords in an encrypted file because it "made more sense" than trying to remember multiple strong passwords.

Another delegate from a government agency, who also requested anonymity, said storing a password list in an encrypted file may work for the administrator but it would not work for users because they would then forget the password to decrypt the password file.

The delegate said that even using two-factor authentication — such as an RSA token — was not safe because people often write their pin number on a piece of paper and tape it to the back of the token.

"I know of a government minister that has done that," the delegate said.


Sponsored Links
#35278 - 05/23/05 04:18 PM Re: Security guru backs writing down passwords
Digital Geek Offline
UGN Super Poster

Registered: 09/18/02
Posts: 553
Loc: Cluj-Napoca, Romania
well, he is a microsoft security guru ... so that explains everything

#35279 - 05/23/05 11:49 PM Re: Security guru backs writing down passwords
Gremelin Offline

Community Owner

Registered: 02/28/02
Posts: 7193
Loc: Portland, OR; USA
I'm not going to bother reading this story to see what reasoning he has; but I'd like to add that there is no reason to write passwords down, people can easily "lift" papers and some have photographic memories...

People are tools, especially listening to morons such as this...
Donate to UGN Security here.
UGN Security, Back of the Web, Elite Web Gamers & VNC Web Design Owner


Featured Member
Registered: 04/29/15
Posts: 2
Forum Stats
2158 Members
46 Forums
41462 Topics
76636 Posts

Max Online: 1567 @ 04/25/10 02:20 AM
Top Posters
UGN Security 34624
Gremelin 7193
§intå× 3255
SilentRage 1273
Ice 1146
pergesu 1136
Infinite 1041
jonconley 955
Girlie 908
unreal 860
Newest Members
Herbert_Sherbert, codemauve, Lillysdragon1984, Brewwit, Suri John
2157 Registered Users
Who's Online
0 registered (), 279 Guests and 201 Spiders online.
Key: Admin, Global Mod, Mod
Latest News

  Get Firefox!
Get FireFox!