On mySimon: Clip On Golf Bag Pocket Watch
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 21 of 27:
Next »
« Previous
Writing down passwords
To me, it is acceptable to write down a password until one has memorized it, provided that the paper remains in the posession of the user at all times (where other people can't see it, like a purse or wallet) and is disposed of securely once it is no longer required. Leaving passwords on one's desk or monitor is completely unacceptable and should be a firing offense. Alternatively, if a sysadmin can find out what a user's password is, he should be required to change it and then notify the user that the password has been changed (or maybe let the user guess!).

For any security policy to be effective, however, it must have the full support of top management and there can be no exceptions (even for the CEO). This usually requires the boss to have a sense of humor. It also goes against millenia-old traditions of enforcing rules more leniently on the aristocracy than on ordinary citizens, but such traditions cause all manner of other problems and should be abolished (if anything, executives should be punished more, not less, harshly for breaches of the rules than ordinary employees).
Posted by: John L. Ries   Posted on: 10/18/06 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Hmmm, well if there are no percieved  Linux User 147560 | 10/17/06
Message has been deleted.  nightman45 | 10/17/06
Message has been deleted.  DarbyOhara | 10/17/06
gah  nhac | 10/17/06
Password Shinanigans  zenwalker | 10/17/06
Deal with it like everyone else  ibabadur1 | 10/18/06
Nice huh?  dkunzman@... | 10/18/06
Not so simple  BobF_z | 10/18/06
Unrealistic!  DarbyOhara | 10/18/06
This should tell us something  LordLiverpool | 10/18/06
Biometrics  wjkahlssmd@... | 10/18/06
Mugging  BobF_z | 10/18/06
Biometrics...  porsche_914 | 10/18/06
Passwords are simple  ibabadur1 | 10/18/06
Thank you, Captain Obvious  ejhonda | 10/18/06
I agree - this isn't news  fnash | 10/19/06
Cleaning people of high rise buildings...  vlad824 | 10/18/06
Pfft, *I* write down the occasional password  CobraA1 | 10/18/06
Before you coment.  infernalburn00 | 10/18/06
SKITTLES***  infernalburn00 | 10/18/06
Writing down passwords  John L. Ries | 10/18/06
People write down passwords?? whats new!  michael_orton@... | 10/18/06
Study: Humans often need oxygen  Tomzda | 10/18/06
SecurID is an excellent answer  ~doolittle~ | 10/18/06
Yes, the 'have a thing and know a thing' combo...  JonathonDoe | 10/18/06
And then the problem is  ghastly | 10/18/06
When you have 15-30 passwords, what else is someone going to do?  BitTwiddler | 10/18/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement
  • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
  • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
  • Smart People The best and worst moves in the management and strategy trenches. Learn More