Jump to content

Recommended Posts

Posted

There's a relevant XKCD (there's always a relevant XKCD) about passwords, but can't get on it at work.

People are being conditioned to pick passwords that are hard for humans to remember, but easy for computers to guess. Longer passwords would be more secure than bogus complexity.

  • Thanks 1
Posted

Line 01 makes me think the author is woefully uninformed, out of date with common password cracking techniques and has no business providing IT guidance to anyone.

Line 02, while not particularly great will generate memorable passwords that will at least be better than the ones created by 01 and 03.

Line 03 suffers from the same problem Line 01 does.

 

More interesting is this:

 

• The ‘Administrator’ passwords for the school ICT system, used by the ICT Technician/Network Manager are also available to the ICT Subject Leader and must be stored securely in school.

 

Implies singular passwords, non-emergency use as commonplace and left with someone who does not need and should not have that level of access unless they regularly perform a role that requires it. Emergency sysadmin-hit-by-a-bus passwords should be stored sealed in the school safe and made available to SLT (who may then choose to delegate tasks to competent staff). A Head of IT (unless they're ye olde Swiss-Army HeadOfIT/Technician/CanYouMendTheKettleToo) doesn't need that access to perform their role and (IMO) should be actively refusing it from a self-preservation perspective.

  • Thanks 1
Posted
People are being conditioned to pick passwords that are hard for humans to remember, but easy for computers to guess.

I am not sure that is such a problem. Realistically, I don't think that the risk to our network security comes from someone running password crackers or brute force attacks on our remote logon system; I think the risks faced in schools are students trying to log in as teachers. Therefore as long as you have a policy which prevents staff members using %Spouse'sName%1, %Dog'sName%2012 etc, you've covered the main threat.

 

Imposing a minimum length of 8-10 characters will help prevent shoulder surfing, and requiring capital letters somewhere (ideally not the first character!) helps ensure that even if you know the base word, (i.e. my cat's name) you still can't log in as me.

Posted
We have the xkcd cartoon blown up to a3 on our wall... The kids don't get it, but we now have maths teachers and a-level students trying to make difficult to guess passwords. The current winner is one that has defeated ophcrack, the student won't tell us what it was!
Posted
I'd be interested to know how many people in Wokingham have the password of "sn0wt1me".

 

I suspect at least one in each location that received that document. Expanding your dictionary to passwords that riff off the same theme (snowtime/winter) would probably yield further results.

 

It's just as well we don't use our powers for evil or my end-users would have funded my Volcano Lair of Doom multiple times over.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...