Archive for July 13th, 2009

SDRNews: Passwords and Policies – Stronger May be Weaker

Play
  • Strong Passwords May Be Costly
  • Google and Microsoft Gone MAD
  • Skipping Windows 7
SDR 125x50
    • Strong Passwords May Be Costly
    • Google and Microsoft Gone MAD
    • Skipping Windows 7

    SDR News is a Daily (M-F) Technology Podcast with Tech News Highlights from Slashdot, Digg and Reddit

    Click Here to Sign Up for the SDR Newsletter

    Podtrac Player
    Prefer a Direct Download ? (mp3)

    Download today’s show.


    If a news item has disappeared from the Del.icio.us list above, try the full list here.


    SEARCH ANY STORY YOU HEAR ON THE PODCAST


    Passwords and Policies

    by Andrew McCaskey
    Worth Noting, Again: Password Strength and Security May Not be Related

    Always worthwhile to question how much security is really added by password rules and policies. The latest paper by Bruce Schneier notes once again that strong password policies tend to add little to the security posture, especially in the face of keyloggers and phishing attacks that exploit weaknesses in physical access or social engineering.

    The combination of more complex user ID’s and shorter passwords (with a three tries rule) seems to offer more protection than enforcing use of more robust passwords. The most destructive combination of all seems to be forced password rotation every few weeks.encouraging trivial passwords with minor rotations ot tweaks. That’s because they are easiest to remember. Human behavior is so messy, yet predictable.

    Contact Us

    Preview of Office 2010

    Watch Today’s Video Episode

    Be sure to check out GoToMeeting. Why? Because you can hold meetings right over the Net — from anywhere. Plus, you can hold all the meetings you want for one flat rate. To get your free 30-day trial , visit www.gotomeeting.com/techpodcasts.

    468x60_free_email_10.gif