sippo Posted November 2, 2017 Posted November 2, 2017 What are people's thoughts on this? We have a policy in place for users to change their passwords every 100 days or so. Standard 8 characters, 1 number, capital letter. I am thinking of changing the character length but extend the time change. Anyone use 2 layer authentication?
mavhc Posted November 2, 2017 Posted November 2, 2017 Passwords for what? Local and internet passwords have different requirements, and different people hacking them. Internet passwords have an attack surface of 510 million km², Local passwords more like 1km². Firstly passwords are a terrible idea, log in with your phone or a usb thing, especially for internet. Secondly make it policy that if anyone else knows your password and you don't change it, you're in trouble. Thirdly monitor password attempts, and successes. What I really want is for the webcam to take a photo of the person typing in the password. If there's no one visible disallow login, if there is, either match, or just save it for auditing. Install a password safe like LastPass for internet passwords, so users only need to remember 2, local computer and password safe password. For Staff with their own laptop have 30 days 2 factor remembering, as it's likely that it's not them when their account is tried on another computer. If you can remember any internet passwords that don't have 2 factor, you're doing it wrong.
enjay Posted November 9, 2017 Posted November 9, 2017 To be honest, I think you're addressing the wrong thing - the hole in your password security isn't the complexity or age, it is the number of passwords which are written on post-it notes on people's desks. We haven't had a successful external hack, however have had instances of people finding passwords and logging in. This will only worsen if you increase the complexity requirements, of course. 1
mavhc Posted November 9, 2017 Posted November 9, 2017 To be honest, I think you're addressing the wrong thing - the hole in your password security isn't the complexity or age, it is the number of passwords which are written on post-it notes on people's desks. We haven't had a successful external hack, however have had instances of people finding passwords and logging in. This will only worsen if you increase the complexity requirements, of course. Which is why you need a password manager installed on all your computers, and lessons on how to use it
MatthewL Posted November 9, 2017 Posted November 9, 2017 Smartcard or proximity fob to login, SSO also setup, user removes fob to gain access on door, PC auto locks. Smartcard similar idea, but can set pin number, get them to set same as bank card will never forget! Just options, not cheap but resolves some issues.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now