On Mon, 2005-04-18 at 13:30 -0400, Peter E. Abresch Jr. - at Pepco
wrote:
> I have a requirement to strengthen our Linux passwords on SuSE Linux
> SLES8. Our requirement are:
>
> Password length 8
> At least one digit
> At least on uppercase letter

I made a suggestion over at Slashdot a couple of months ago, and the
peanut gallery modded me "funny".  Maybe this crowd will take me a
little more seriously.

Complex password rules work at cross-purposes: they encourage people to
write down their passwords, something you DON'T want to happen.  Forced
password changes encourage them to rotate their passwords in predictable
ways: Dave01 in January, Dave02 in February, and so on.

You WANT them to have passwords that are easy to remember, but aren't
subject to dictionary or brute-force attack.

So saddle *them* with the responsibility.  Get rid of all your password
rules.  Tell your employees that they can choose any passwords they
like... with the understanding that you are going to run a password
cracker 24 hours per day.  And if their passwords are cracked, then
they're fired, simple as that.

--
David Andrews
A. Duda and Sons, Inc.
[EMAIL PROTECTED]

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390

Reply via email to