Re: New Password rules at VRM610
Simon Coulter <shc-Q/[email protected]> Wed, 23 Apr 2008 07:50:15 +1000
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <[email protected]> |
On 23/04/2008, at 4:14 AM, David Gibbs wrote:
> Of course, one thing that all security administrators need to keep in
> mind is the usability of the password restriction scheme that they
> choose.
>
> Overly complex password restrictions lead to forgotten passwords,
> passwords on post-it notes, automatically stored passwords, etc.
>
> The more complex security you put in place, the less security you
> end up
> having.
True, but you can teach users how to compensate and still satisfy
many requirements. For example, teach them to replace O by 0, I by 1,
E by 3, etc. Thus you can remove vowels (harder to guess passwords)
and require at least one digit (harder to guess passwords).
Regards,
Simon Coulter.
--------------------------------------------------------------------
FlyByNight Software OS/400, i5/OS Technical Specialists
http://www.flybynight.com.au/
Phone: +61 2 6657 8251 Mobile: +61 0411 091 400 /"\
Fax: +61 2 6657 8251 \ /
X
ASCII Ribbon campaign against HTML E-Mail / \
--------------------------------------------------------------------
_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.