by sjvn
Security

Avoiding Password Hell

Some people seem to think that long, complicated passwords that change frequently are great for security. They couldn't be more wrong.

2 comments | 8I like it!
October 28, 2009, 11:11 AM — 

After pointing out that running multiple anti-virus or firewall programs on the same PC is a really bad security idea, some of my readers reminded me that that's not the only common, but stupid, idea people have about security. Another far too popular, and dumb, idea is that making users use long, complicated passwords that change frequently is good for security. No, it's not.

As Jonathan Yarmis, a research fellow at the research company Ovum, pointed out to me, "My favorite is onerous password requirements. 17 letters, characters and numbers. Changed every 30 days. No repeats nor anything similar. GUARANTEES that the person has to write it down within 5 feet of their computer."

Yep, he's got that right. If you make your password policy a major pain-in-the-rump you'd just make it a sure thing that no one will use their passwords safely. Yarmis isn't make his example up. I knew one company where the passwords had to be 20-characters long and changed every month. Of course, no one at that business took their password policy seriously and, sure enough, they had their servers raided within a year.

If you make basic security hard to do, you only make certain that it won't be used. It's really that simple.

Of course, writing down your passwords may not be that awful an idea. As no less a figure than security guru Bruce Schneier wrote, "Simply, people can no longer remember passwords good enough to reliably defend against dictionary attacks, and are much more secure if they choose a password too complicated to remember and then write it down. We're all good at securing small pieces of paper. I recommend that people write their passwords down on a small piece of paper, and keep it with their other valuable small pieces of paper: in their wallet."

Notice though that he said to keep in your wallet, or some other reasonably secure location. I mean, you may not notice if a piece of paper on your desk disappears, but you'll certainly know if your wallet goes missing.

But what about if you have to deal with dozens of passwords for multiple Web sites? You could put those passwords on paper, but with as many passwords as we're stuck with using these days that can quickly become a pain in its own right.

At the same time, the last thing you want to do is to make those classic mistakes of using your name, wife's name, etc. as a password. That's just asking for someone to get into your accounts.

What I use these days for managing my mess of passwords are password managers. Some operating systems, like Mac OS X and Linux, have programs such as KeyChain to help you keep track of your passwords while maintaining their security.

Sign up for ITworld's Daily newsletter
Follow ITworld on Twitter @IT_world

I like it!
Comments

Password Hell

Have dozens of passwords to remember? Get and use Roboform. It's free and you only have to type in your password once. You can even encrypt the program so you only have to remember one password if you so desire. And when you have to change your password, Roboform pops up so you can tell it to remember the new one. The program is also handy in that you click in the password which pretty much defeats keystroke loggers.
| reply

Totally Agree

My company required change password every 28 days.
Rules: Number + Char (upper and lower case) + Symb and Min 9 Words and can't be repeated..

For me, it just make less security rather than change it every 3 months.. who can remember those password unless they using dictionary word ??
| reply
peer-to-peer

Esther Schindler
If the comments are ugly, the code is ugly

claird
SVG a graphics format for 21st century

pasmith
Take Chrome OS for a test spin

Sandra Henry-Stocker
Solaris Tip: Have Your Files Changed Since Installation?

sjvn
64-bits of protection?

jfruh
Android fragments vs. the iPhone monolith

mikelgan
What Gizmodo missed about the Pro WX Wireless USB disk drive

 

Sidekick: The Good News & the Bad News
Either way you look at it Microsoft Data Center management did not follow standards or best practices in this failure. In which case it makes me wonder more about the outsourcing of corporate data much less personal data.
- mburton325

Join the conversation here

The Daily Tip

The Daily TipQuick, practical advice for IT pros. Made fresh daily.

Hot tips:

Want to cash in on your IT savvy? Send your tip to tips@itworld.com. If we post it, we'll send you a $25 Amazon e-gift card.

Newsletters

Subscribe to ITWORLD TODAY and receive the latest IT news and analysis.

I would like to receive offers via email from ITworld partners.
By clicking submit you agree to the terms and conditions outlined in ITworld's privacy policy.
Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

Marketplace