
It's better than using the same one for all...
Published: 23 May 2005 09:40 BST
Companies should not ban employees from writing down their passwords because it forces users to use the same weak term on many systems, according to a Microsoft security guru.
Speaking on the opening day of the AusCERT conference on Australia's Gold Coast, Jesper Johansson, senior programme manager for security policy at Microsoft, said the security industry had been giving out the wrong advice to users by telling them not to write down their passwords.
"How many have password policy that says under penalty of death you shall not write down your password?" asked Johansson, to which the majority of delegates raised their hands in agreement. "I claim that is absolutely wrong. I claim that password policy should say you should write down your password. I have 68 different passwords. If I am not allowed to write any of them down, guess what I am going to do? I am going to use the same password on every one of them," he said.
According to Johansson, use of the same password reduces overall security.
"Since not all systems allow good passwords I am going to pick a really crappy one, use it everywhere and never change it. If I write them down and then protect the piece of paper - or whatever it is I wrote them down on - there is nothing wrong with that. That allows us to remember more passwords and better passwords," said Johansson.
Johansson said the security industry had been giving out the wrong advice about passwords for 20 years.
Delegates at the conference agreed that Johansson's advice made sense. However, they did not think it was practical.
One IT administrator from an international entertainment company, who requested anonymity, said that despite it being strict company policy to not make a note of passwords, he collated his personal passwords in an encrypted file because it "made more sense" than trying to remember multiple strong passwords.
Another delegate from a government agency, who also requested anonymity, said storing a password list in an encrypted file may work for the administrator but it would not work for users because they would then forget the password to decrypt the password file.
The delegate said that even using two factor authentication - such as an RSA token - was not safe because people often write their pin number on a piece of paper and tape it to the back of the token.
"I know of a government minister that has done that," the delegate said.
Munir Kotadia writes for ZDNet Australia
I've been using "Whister32" (encrypted notepad) fo...
Anonymous
Writing down passwords is eminently sensible advic...
Murdoch Mactaggart
You are obviously not a security conscious individ...
Anonymous
Simple encryption is the answer.
Writing down pas...
Dozza
Remembering passwords can be a problem for some wi...
Lionel A Smith
Previous experience and understanding of backup system such as; - File system back up - Application backup method - Different backup levels - ...
The main duties include: updating and tracking incidents raised against the systems, logging and tracking change requests and the preparation of ...
This is green field development offering design, development, architectural and managerial opportunities. You must have had vast experience working ...
CIO Agenda 2008
The exclusive silicon.com CIO Agenda 2008 survey looks at the CIO's tech shopping list for the year, examines whether IT budgets are rising or falling and reveals what the pain points are for tech chiefs this year. Find out more in our latest special report.
Staffing Service Coordinates Sales Activities, Utilizes Business Intelligence With...
Teachers Association Turns to Centralized Data Repository to Improve Member Service
Financial-Software Leader Credits Productivity Boost, Reduced IT Costs to 2007 Software
Staying Ahead of the Curve: Oracle Database 11g vs. Microsoft SQL Server 2005
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
silicon.com Dear silicon.com... XP lives, the femtocell 'truth', BlackBerry bashing… Reader Comments of the Week
Martin Brampton The Brampton Factor: Open source 'brotherhood' closed to co-operation Where's the real sharing?