Thursday, March 18, 2010

Bookmark and Share

Archive for the ‘Passwords’ Category

“. . .the wretched way the world is.”

That’s John Callas, CTO of PGP Corp, on the multiple password issue. The whole article is a good read, quoting a poll by searchsecurity.com that found “77% of respondents had six or more passwords to remember for their jobs.”

The password issue’s a tricky one. The proliferation of password-based access to data, networks, and applications has left almost all users with the problem of password juggling. SSO and other attempts to reduce passwords have their own problems, single point of failure being one of the nastiest.

If I had a solution to the problem, I’d be a wealthy woman. In the meanwhile, companies will do well to train their users on how to select secure passwords and, something that’s often overlooked, instruct users not to use these passwords for external access. While cracking a password for an internal corporate system may be fairly difficult, cracking a password for a hotmail account, depending on the vulnerability du jour in the hotmail system, often isn’t. If an employee is re-using internal passwords for access to external information there’s a potential vulnerability.

So train users to guard their internal passwords carefully.

Bookmark and Share
“Comprehensive, detailed, and trustworthy guidance in the information security market.”
Blog Cloud

The Law: Fear It Administrative Cruft (16)
Analysts (31)
Apple (25)
AppSec (12)
Assessments (2)
Auditors (2)
Biometrics (4)
Blogs (13)
Breaches (21)
Buzzwords (2)
By Grabthar's Hammer!! (1)
Certifications (1)
Change Management (1)
Cheezburger Network (1)
Chupacabra (1)
Cloud Computing Security (4)
Collaborative Strategy Guild (2)
Compliance (4)
Copyright (9)
Credit Cards (3)
Crypto (11)
CXO Summit 2010 (1)
Cyberterrorism (2)
Data Protection (2)
DHS (25)
eBay (1)
Emergence (1)
End-to-End Encryption (2)
England (1)
Financial Fraud (1)
FISAP (1)
Forensics (5)
FTC Red Flad Rules (1)
FUD (12)
gnisreveR (2)
Google (2)
Holidays! (3)
Humor (16)
Identity Theft (4)
James Bond Shiz (1)
Legal Shiz (13)
Linux (3)
Malware (35)
Marketing and PR (9)
Messaging Security (1)
Microsoft (26)
Monoculture (3)
Mouth-Frothing (2)
Musings (17)
Open Source (3)
Oracle (21)
Outsourcing (4)
Paris Hilton (1)
Passwords (1)
PCI (4)
Phish-Eye (8)
Phones (5)
Planes (1)
Privacy (1)
Programming (1)
QDSP Blues (15)
Research (30)
Resources (6)
Rhesus Monkeys (2)
Risk Management (18)
RSA 2009 (1)
RSA 2010 (1)
SAML (1)
SAN (1)
SC Mag Blues (1)
SCADA (1)
Security Curve (8)
SecurityCurve Speaking (2)
SIEM and Log Management (5)
Social Networking (1)
SOX (1)
Speaking (2)
Spinach (1)
Spy Stuff (1)
Stealing Stuff (8)
Storage (1)
Symantec (7)
Tarot (1)
Teleological suspension of the ethical (3)
The Great Borack (1)
The Law: Fear It (10)
The Old Man of the Mountain (1)
The Regs (5)
Tokenization (1)
Useless Shizz (13)
Vendors (37)
Virtual Worlds (2)
Voting (2)
Vulnerabilities (40)
Walt Disney (2)
Wi-Fi (16)

WP Cumulus Flash tag cloud by Roy Tanck and Luke Morton requires Flash Player 9 or better.

Archives