Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book General > General Discussions

Notices

Reply
 
Thread Tools Search this Thread
Old 11-11-2010, 01:43 PM   #46
Worldwalker
Curmudgeon
Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.
 
Posts: 3,085
Karma: 722357
Join Date: Feb 2010
Device: PRS-505
A basic dictionary attack will be detected within a few tries; it's not like the old days. If they're stealing the password file and attacking that, the solution is better system security, not weaker user security, and if they've got enough of a massively parallel system (or perhaps a botnet) to try every option against the hashes, requiring unmemorable characters in users' passwords will not make it measurably slower. A disturbingly common point of attack is stolen (or just lost) laptops with passwords on them. The world's most secure password doesn't do jack for a trojaned, stolen, or otherwise suborned computer. Making the users write their passwords down, or store them in their laptops, as Duncan says, is making the problem worse instead of better.

I did once have a nice consulting gig resetting an office manager's password every 90 days. He always ignored the "grace period" messages, then called in great distress when his old password didn't work anymore, giving me a nice drive and some free money for 5 minutes' work. Unfortunately, it wasn't long before they bought a system that didn't suck. I miss that one.
Worldwalker is offline   Reply With Quote
Old 11-11-2010, 02:14 PM   #47
MikeFromHC
Zealot
MikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-books
 
Posts: 143
Karma: 880
Join Date: Jun 2010
Device: Pandigital Novel
Quote:
Originally Posted by DuncanWatson View Post
That problem relates to IT departments mandating 90 day changes of passwords with no repeats for the last 10 passwords and a mandate of 90% change for the new password as compared to the last 10 used. As well as mixed numbers, letters and punctuation.

Shockingly such draconian user-unfriendly policies result in rampant security violations as users put passwords on sticky notes, in their wallets, on their pda/phones etc. Sure some people (this is especially bad in accounting and financial departments) will put passwords on sticky notes attached to their monitor no matter what you do. But by making it so unfriendly many more users are forced to take such action just to be able to do their job. Not everyone can create passwords that fit IT criteria of a good password and commit them to memory every 3 months. Especially without reuse. If you really need such security use an skey token with generated passwords every 30 seconds or so. (something you have + something you know security).
The IT department is responding to *known* threats and such measures are the only ways known to protect access to the information.

Note I said "responding" as these measures are put in place after somebody finds out the hard way about the problem.
MikeFromHC is offline   Reply With Quote
Old 11-11-2010, 02:27 PM   #48
Worldwalker
Curmudgeon
Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.
 
Posts: 3,085
Karma: 722357
Join Date: Feb 2010
Device: PRS-505
The problem is that by responding to one problem (systems vulnerable to dictionary attacks) they're creating another problem (user passwords that can't be remembered) -- and the new problem may, in fact, be worse than the old problem.
Worldwalker is offline   Reply With Quote
Old 11-11-2010, 06:36 PM   #49
Harmon
King of the Bongo Drums
Harmon ought to be getting tired of karma fortunes by now.Harmon ought to be getting tired of karma fortunes by now.Harmon ought to be getting tired of karma fortunes by now.Harmon ought to be getting tired of karma fortunes by now.Harmon ought to be getting tired of karma fortunes by now.Harmon ought to be getting tired of karma fortunes by now.Harmon ought to be getting tired of karma fortunes by now.Harmon ought to be getting tired of karma fortunes by now.Harmon ought to be getting tired of karma fortunes by now.Harmon ought to be getting tired of karma fortunes by now.Harmon ought to be getting tired of karma fortunes by now.
 
Harmon's Avatar
 
Posts: 1,632
Karma: 5927225
Join Date: Feb 2009
Device: Excelsior! (Strange...)
"Always tell the truth. This will please some people & astonish the rest." - Mark Twain.
Harmon is offline   Reply With Quote
Old 11-11-2010, 11:00 PM   #50
thrawn_aj
quantum mechanic
thrawn_aj ought to be getting tired of karma fortunes by now.thrawn_aj ought to be getting tired of karma fortunes by now.thrawn_aj ought to be getting tired of karma fortunes by now.thrawn_aj ought to be getting tired of karma fortunes by now.thrawn_aj ought to be getting tired of karma fortunes by now.thrawn_aj ought to be getting tired of karma fortunes by now.thrawn_aj ought to be getting tired of karma fortunes by now.thrawn_aj ought to be getting tired of karma fortunes by now.thrawn_aj ought to be getting tired of karma fortunes by now.thrawn_aj ought to be getting tired of karma fortunes by now.thrawn_aj ought to be getting tired of karma fortunes by now.
 
thrawn_aj's Avatar
 
Posts: 705
Karma: 483827
Join Date: Aug 2010
Location: NorCal
Device: Nook1, Samsung Transform, Nook2
Quote:
Originally Posted by Figwit View Post
You could always try www.bugmenot.com
I've used bugmenot to good avail in the past. I would be careful with it though - it's like anything you find lying in the street and decide to take home. Who knows what people have done with some of those usernames in the past?
thrawn_aj is offline   Reply With Quote
Old 11-12-2010, 03:02 AM   #51
MikeFromHC
Zealot
MikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-books
 
Posts: 143
Karma: 880
Join Date: Jun 2010
Device: Pandigital Novel
Quote:
Originally Posted by Worldwalker View Post
The problem is that by responding to one problem (systems vulnerable to dictionary attacks) they're creating another problem (user passwords that can't be remembered) -- and the new problem may, in fact, be worse than the old problem.
It may be more work for IT but if you had to decide between having your valuable information taken because somebody thought "Password" was a good password (and there was a time when it was, sans network, sans Internet) and having to reset for people not smart enough to find a good easy to remember password, which would you pick?

Essentially the same method can be used to remember a password or stars

ObAfGkMrNs
MikeFromHC is offline   Reply With Quote
Old 11-12-2010, 09:49 AM   #52
Worldwalker
Curmudgeon
Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.
 
Posts: 3,085
Karma: 722357
Join Date: Feb 2010
Device: PRS-505
I don't think either one is a viable solution (and I say this as someone who once had a very nice consulting gig regularly resetting an office manager's password). One gives you hard-to-find weak passwords, the other gives you easy-to-find strong passwords (the stickynotes). While getting users to choose at least moderately strong passwords is important, so is hardening the system as a whole. So, too, is setting appropriate user privileges and access. That's definitely more work for IT, but it has the advantage of working, and not just forcing users to write their passwords in places you don't want to think about. Remember, we're talking about Jersey Shore fans here: they're not gonna memorize passwords or stars.
Worldwalker is offline   Reply With Quote
Old 11-12-2010, 10:00 AM   #53
Merbear
Enthusiast
Merbear put the bomp in the bomp-a-bomp-a-bomp.Merbear put the bomp in the bomp-a-bomp-a-bomp.Merbear put the bomp in the bomp-a-bomp-a-bomp.Merbear put the bomp in the bomp-a-bomp-a-bomp.Merbear put the bomp in the bomp-a-bomp-a-bomp.Merbear put the bomp in the bomp-a-bomp-a-bomp.Merbear put the bomp in the bomp-a-bomp-a-bomp.Merbear put the bomp in the bomp-a-bomp-a-bomp.Merbear put the bomp in the bomp-a-bomp-a-bomp.Merbear put the bomp in the bomp-a-bomp-a-bomp.Merbear put the bomp in the bomp-a-bomp-a-bomp.
 
Merbear's Avatar
 
Posts: 38
Karma: 67710
Join Date: Jul 2010
Location: Ontario
Device: PRS-600 & Kobo & PRS-650, iTouch and iPad2
the most annoying on-line store I found was Plimus in Britain. When I was in Thailand last month my daughter wanted the Ngaio Marsh books they advertised. I bought them for download on-line and paid immediately with PayPal but they just about wanted my life history including phone number and then I had to wait several days for a download link! For goodness sakes - it cost $9.99.
Merbear is offline   Reply With Quote
Old 11-12-2010, 06:29 PM   #54
Seanette
Addict
Seanette has learned how to read e-booksSeanette has learned how to read e-booksSeanette has learned how to read e-booksSeanette has learned how to read e-booksSeanette has learned how to read e-booksSeanette has learned how to read e-booksSeanette has learned how to read e-books
 
Seanette's Avatar
 
Posts: 254
Karma: 834
Join Date: Oct 2010
Location: Sacramento, CA
Device: Samsung Galaxy s3 (Android 4.4.2), iPad 2, Win10 laptop
Quote:
Originally Posted by DuncanWatson View Post
That problem relates to IT departments mandating 90 day changes of passwords with no repeats for the last 10 passwords and a mandate of 90% change for the new password as compared to the last 10 used. As well as mixed numbers, letters and punctuation.
And differing cycles/requirements for each of several logins needed to perform one's work.

I've been known to resort to the "list on my PDA that doesn't leave my physical possession while at work" strategy myself.
Seanette is offline   Reply With Quote
Old 11-13-2010, 01:13 AM   #55
MikeFromHC
Zealot
MikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-books
 
Posts: 143
Karma: 880
Join Date: Jun 2010
Device: Pandigital Novel
Quote:
Originally Posted by Worldwalker View Post
I don't think either one is a viable solution <snip>
Remember, we're talking about Jersey Shore fans here: they're not gonna memorize passwords or stars.
Which is why all they have to do is remember a simple personal question and apply a simple set of rules they make up.

If they can't do that then perhaps people who can should be hired.
MikeFromHC is offline   Reply With Quote
Old 11-13-2010, 08:34 AM   #56
Worldwalker
Curmudgeon
Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.
 
Posts: 3,085
Karma: 722357
Join Date: Feb 2010
Device: PRS-505
Quote:
Originally Posted by MikeFromHC View Post
If they can't do that then perhaps people who can should be hired.
In my experience, the worst offenders are those who do the hiring. When I went to a client's site every 90 days to fix a guy's password, it wasn't some peon's password that needed changed; it was the head of the regional office.
Worldwalker is offline   Reply With Quote
Old 11-13-2010, 08:30 PM   #57
meromana
Zealot
meromana can tame squirrels without the assistance of a chair or a whip.meromana can tame squirrels without the assistance of a chair or a whip.meromana can tame squirrels without the assistance of a chair or a whip.meromana can tame squirrels without the assistance of a chair or a whip.meromana can tame squirrels without the assistance of a chair or a whip.meromana can tame squirrels without the assistance of a chair or a whip.meromana can tame squirrels without the assistance of a chair or a whip.meromana can tame squirrels without the assistance of a chair or a whip.meromana can tame squirrels without the assistance of a chair or a whip.meromana can tame squirrels without the assistance of a chair or a whip.meromana can tame squirrels without the assistance of a chair or a whip.
 
meromana's Avatar
 
Posts: 129
Karma: 11430
Join Date: Jun 2010
Location: NC, USA
Device: my laptop
Quote:
Originally Posted by MikeFromHC View Post
Which is why all they have to do is remember a simple personal question and apply a simple set of rules they make up.

If they can't do that then perhaps people who can should be hired.
I don't know...in my experience, those who excel at memorizing tedious lists of oddball characters aren't necessarily those who excel at critical, analytical thinking. Like me, for example. In my last job, there were at least 10 different systems requiring 10 different passwords (each system had different password rules), and they had to be changed every 90 days, NOT on the same schedule. Worse yet, if you typed the wrong password 3 times, you were locked out, usually for several hours, and required a manual unlock by some guy in IT.

Of course, unless I was on a tight deadline, I didn't mind that much--I got paid by the hour, even when locked out and unable to do my job. I would guess that password problems cost this company far more than what they saved from any potential security threat that their policies may have prevented.

--Maria
meromana is offline   Reply With Quote
Old 11-13-2010, 11:48 PM   #58
MikeFromHC
Zealot
MikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-books
 
Posts: 143
Karma: 880
Join Date: Jun 2010
Device: Pandigital Novel
Quote:
Originally Posted by meromana View Post
I don't know...in my experience, those who excel at memorizing tedious lists of oddball characters aren't necessarily those who excel at critical, analytical thinking.

--Maria
There is no need to. If you can pick the password simple sentences with simple rules gives passwords that can only be broken with brute force.

Maria, can you remember a simple sentence?
McYra$$?
MikeFromHC is offline   Reply With Quote
Old 11-14-2010, 01:50 AM   #59
Worldwalker
Curmudgeon
Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.Worldwalker ought to be getting tired of karma fortunes by now.
 
Posts: 3,085
Karma: 722357
Join Date: Feb 2010
Device: PRS-505
But this week, is it "Maria, can you remember a simple sentence?" or "Maria, what is that sentence today?" ... and what will it be next week? Joe Schmoe in accounting is just gonna write the thing on a stickynote, and thereby hangs the problem.
Worldwalker is offline   Reply With Quote
Old 11-14-2010, 01:35 PM   #60
MikeFromHC
Zealot
MikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-booksMikeFromHC has learned how to read e-books
 
Posts: 143
Karma: 880
Join Date: Jun 2010
Device: Pandigital Novel
Quote:
Originally Posted by Worldwalker View Post
But this week, is it "Maria, can you remember a simple sentence?" or "Maria, what is that sentence today?" ... and what will it be next week? Joe Schmoe in accounting is just gonna write the thing on a stickynote, and thereby hangs the problem.
If Joe can't remember a sentence he made up then perhaps he needs a job someplace else.
MikeFromHC is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
I didn't mean to offend the Religious Right. Honest. Donna Callea Writers' Corner 38 11-14-2010 11:45 AM
Catch an Honest Thief (cozy mystery - $2.99) BearMountainBooks Self-Promotions by Authors and Publishers 0 08-29-2010 03:40 PM
An honest review of my book... J. Dean Writers' Corner 6 02-17-2010 01:43 PM
A real pain crutledge Workshop 2 08-13-2009 01:15 PM
A real pain crutledge Workshop 0 08-05-2009 11:33 AM


All times are GMT -4. The time now is 05:07 AM.


MobileRead.com is a privately owned, operated and funded community.