Re: New Password rules at VRM610

David Gibbs <david-Zwy7GipZuJhWk0Htik3J/[email protected]> Tue, 22 Apr 2008 13:14:53 -0500
Newsgroups gmane.comp.systems.as400.security
Message-ID <[email protected]>
[email protected] wrote:
> Limiting characters was a good way to forbid words.  Taking out vowels was 
> a common technique.  Removing this capability does not do much for 
> "freedom of choice" for administrators.

Of course, one thing that all security administrators need to keep in 
mind is the usability of the password restriction scheme that they choose.

Overly complex password restrictions lead to forgotten passwords, 
passwords on post-it notes, automatically stored passwords, etc.

The more complex security you put in place, the less security you end up 
having.

david

-- 
IBM System i - For when you can't afford to be out of business

_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.