Re: New Password rules at VRM610

Simon Coulter <shc-Q/[email protected]> Wed, 23 Apr 2008 07:50:15 +1000
Newsgroups gmane.comp.systems.as400.security
Message-ID <[email protected]>
On 23/04/2008, at 4:14 AM, David Gibbs wrote:
> Of course, one thing that all security administrators need to keep in
> mind is the usability of the password restriction scheme that they  
> choose.
>
> Overly complex password restrictions lead to forgotten passwords,
> passwords on post-it notes, automatically stored passwords, etc.
>
> The more complex security you put in place, the less security you  
> end up
> having.

True, but you can teach users how to compensate and still satisfy  
many requirements. For example, teach them to replace O by 0, I by 1,  
E by 3, etc. Thus you can remove vowels (harder to guess passwords)  
and require at least one digit (harder to guess passwords).


Regards,
Simon Coulter.
--------------------------------------------------------------------
    FlyByNight Software         OS/400, i5/OS Technical Specialists

    http://www.flybynight.com.au/
    Phone: +61 2 6657 8251   Mobile: +61 0411 091 400        /"\
    Fax:   +61 2 6657 8251                                   \ /
                                                              X
                  ASCII Ribbon campaign against HTML E-Mail  / \
--------------------------------------------------------------------



_______________________________________________
This is the Security Administration on the AS400 / iSeries (Security400) mailing list
To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected]
To subscribe, unsubscribe, or change list options,
visit: http://lists.midrange.com/mailman/listinfo/security400
or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected]
Before posting, please take a moment to review the archives
at http://archive.midrange.com/security400.