I have a question for the IT guys...

rudeguy

Lifer
Dec 27, 2001
47,371
14
61
What is you guys' fascination with passwords?

I have a password to log onto my machine at work. After I get logged into that, I have 3 different programs that I need up and I have a password for each one of those. Each program has its own "rules" for what/how many characters each password should have. Each program also has differing number of days before the password expires. All these passwords with random rules ends up meaning that I just keep a file on my desktop with a list of all my passwords. I'm sure I'm not the only person who has a "passwords" document on their desktop.

Why can't there just be one password that logs me into everything? Its not like I can get into any of the other systems without my Windows logon. There are about 10 things that run at startup that NEVER get used, why not make the 3 critical programs start up too?

Security you say? Windows locks itself if I am inactive for more than a couple minutes. The other programs also log me off if I don't use them for X amount of time. This means that generally my password file is always up because chances are I am going to use it almost as much as I use Internet Explorer.

Why not make it easier for the thousands (millions?) of us who are just trying to do our jobs?
 

jonks

Lifer
Feb 7, 2005
13,918
20
81
I'm quite sure I have no idea what you are speaking of.



(oh, not "It" guys, IT guys. my bad.)
 

rockyct

Diamond Member
Jun 23, 2001
6,656
32
91
Not to mention that when people are required to use complex passwords that must be changed, most of the time they write them down.
 

Malak

Lifer
Dec 4, 2004
14,696
2
0
The expiring passwords is retarded, but the passwords for each program is to stop other users who aren't authorized. They might be able to get into your user account, but they are much less likely to get into the program after that since the password is most likely different.

Except that is all hypothetical and the password is usually the same password with 1-0 attached to the end.
 

nageov3t

Lifer
Feb 18, 2004
42,816
83
91
my company's password policy is so retarded that it's made my passwords worse -- we have to rotate them so frequently that all I use is the same dictionary word with 1 capitalized letter and a number at the end (and every time it's new password day, I just add a +1 to the number).

but we're shifting towards using tokens for log-ins, which is a pain in the ass in its own special way.
 

Locut0s

Lifer
Nov 28, 2001
22,281
43
91
IT has gone overboard with passwords as a means of security. The more passwords you need to remember, the more often you need to change them, and the more rules you put in place for force people to use strong passwords, the more likely people are going to choose dump passwords. Things like password1, then next week password2, etc etc... Face it this just makes things less secure.

Here is what every company should do. Make every emplyee have 1 or 2 passwords and force them to choose really strong passwords. These passwords NEVER expire. Everything in the entire company uses one of these 2 passwords. VERY strict punishments are put in place for divulging ones password to anyone, up to and including being fired (depending on the sensitivity of the material being worked on). Now place the VAST majority of IT security budget in building a secure infrastructure. Lock everything down. Firewall everything. Limit employees access to only what they need. Record everything. If you follow these rules you don't really need a super secure password that changes every week. Unless you work for the military or something.
 

GeekDrew

Diamond Member
Jun 7, 2000
9,100
13
81
I'm an IT guy, and while I acknowledge the need for passwords and authentication in different apps, resources, etc., I'm a huge fan of SSO. The problem is that most apps are too stupid to utilize SSO.
 

LittleNemoNES

Diamond Member
Oct 7, 2005
4,142
0
0
its because we need to comply with different regulations and to save your butt and the bosses.

It is a necessary evil.

Before I came in, the secretary's password was 1111
The HRO department lady's password was ... hro

Just these 2 stupid passwords put everyone's social security and bank account numbers at risk!
 

Locut0s

Lifer
Nov 28, 2001
22,281
43
91
its because we need to comply with different regulations and to save your butt and the bosses.

It is a necessary evil.

Before I came in, the secretary's password was 1111
The HRO department lady's password was ... hro

Just these 2 stupid passwords put everyone's social security and bank account numbers at risk!

Yeah but with rotating passwords every week you now have this problem

Week1:

Secretary: 111
HRO: hroA


Week1:

Secretary: 222
HRO: hroB

Week1:

Secretary: 333
HRO: hroC

Week1:

Secretary: 444
HRO: hroD

etc etc....

Just force them to choose 1 highly secure password or have one auto-generated for them. Like 1d56!. Then make sure there are really sever punishments for leaking passwords or writing them down.
 

Bateluer

Lifer
Jun 23, 2001
27,730
8
0
Yeah but with rotating passwords every week you now have this problem

Week1:

Secretary: 111
HRO: hroA


Week1:

Secretary: 222
HRO: hroB

Week1:

Secretary: 333
HRO: hroC

Week1:

Secretary: 444
HRO: hroD

etc etc....

Just force them to choose 1 highly secure password or have one auto-generated for them. Like 1d56!. Then make sure there are really sever punishments for leaking passwords or writing them down.

Passwords should still be rotated after a given time. There's no need to rotate the password every 30 days, unless you're dealing with some super classified project, but to have the same password for years is idiotic.
 

LittleNemoNES

Diamond Member
Oct 7, 2005
4,142
0
0
Passwords should still be rotated after a given time. There's no need to rotate the password every 30 days, unless you're dealing with some super classified project, but to have the same password for years is idiotic.

yeah

Through GPO my password never expires but it is pretty tough to figure out cos I use a mnemonic to remember it :awe:
 

ultimatebob

Lifer
Jul 1, 2001
25,135
2,445
126
Single Sign-on FTMW!!!!

Yeah... any Microsoft shop worth it's salt should allow you to use your Active Directory ID to log onto your PC, Outlook, Network share, VPN, and Messenger accounts. Bonus points if you can use that same ID to log onto your Intranet and CRM apps as well.

UNIX shops can do similar tricks with NIS and LDAP, but it isn't nearly as easy to set up.

You're still going to need a BIOS power-on password if you want your mobile assets to be secure, but you DON'T have to have a dozen different passwords to be secure if you do it right.
 

alkemyst

No Lifer
Feb 13, 2001
83,967
19
81
I require a 40 character hash with no english words contained within, this must be updated every 7 days and include no characters in the same spots or in any same sequence.
 

Evadman

Administrator Emeritus<br>Elite Member
Feb 18, 2001
30,990
5
81
For some of the systems I access, I need both a password that is required to be changed every 7 days, and a password that rotates every 10 minutes on a physical device I have in my possession. Without both, I can't get in.
 

rudeguy

Lifer
Dec 27, 2001
47,371
14
61
I no longer know what the majority of my passwords are thanks to this. One passphrase to rule them all!

Did I mention that our rigs are locked down so tight that we had to fight to be able to unlock our taskbars?

Its not like I work with sensitive info or anything. Well I guess having access to people's porn watching habits is kinda sensitive...
 

Imp

Lifer
Feb 8, 2000
18,829
184
106
I have 3 different passwords at work. Two for programs I rarely use, so after forgetting one, and going through helpdesk, I wrote them down and out it on my shelf.
 

Malak

Lifer
Dec 4, 2004
14,696
2
0
Yeah... any Microsoft shop worth it's salt should allow you to use your Active Directory ID to log onto your PC, Outlook, Network share, VPN, and Messenger accounts. Bonus points if you can use that same ID to log onto your Intranet and CRM apps as well.

When I was in IT, that's how we handled it. All our apps were developed in-house and designed to only allow specific users access.
 

alkemyst

No Lifer
Feb 13, 2001
83,967
19
81
Did I mention that our rigs are locked down so tight that we had to fight to be able to unlock our taskbars?

Its not like I work with sensitive info or anything. Well I guess having access to people's porn watching habits is kinda sensitive...

The idea of locking a taskbar is to keep the IS staff from handling calls on "why is my taskbar [so big, gone, on the top of the screen, has all these icons on it/has no icons on it]" etc.

Windows policies <> password
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |