Re: [Sigia-l] Password usability

Andrew Boyd <[email protected]>
Newsgroups gmane.comp.web.sigia
Message-ID <[email protected]>
On Sat, Dec 11, 2010 at 4:01 AM, Jayson Elliot <[email protected]> wrote:
> There is a lot of research that I can find about security policies and
> usability when it comes to user passwords.
>
> What I'm not able to find, however, is anything related to policies with
> FORBID special characters. We have a security specialist in IT who is
> insisting that the password policy must forbid special characters, because
> "special characters give users too many options to forget."
>
> This sounds ludicrous on the face of it to me, because merely giving people
> the option to choose special characters is not the same thing as requiring
> them. If someone has a favorite password which contains an exclamation mark,
> for example, forcing them to use a different password could result in their:
> A) Selecting a password that they can't remember
> or
> B) Giving up during registration and not completing the process.
>
> Does anyone know of a white paper or research that addresses this issue?

Jayson,

having worked both sides of the information security fence, I'd be
spinning this one around and asking your IT security colleague to
supply some research. So many organisations get into trouble because
of baseless IT security voodoo - if I had a dollar for every time I've
heard "we need CAPTCHA because it prevents DoS attacks" I'd be richer.
Needful security is, well, needed - and everything else that prevents
customer/client/staff task execution just needlessly threatens the
bottom line.

Cheers, Andrew

-- 
---
Andrew Boyd
http://uxbookclub.org -- connect, read, discuss
------------
2011  IA Summit
March 30 - April 3, 2011
Pre Conference Seminars: March 30-31
IA Summit: April 1-3
Hyatt Regency Convention Center
Denver, CO 
-----
When replying, please *trim your post* as much as possible.
*Plain text, please; NO Attachments

Searchable Archive at http://www.info-arch.org/lists/sigia-l/
________________________________________
Sigia-l mailing list -- post to: [email protected]
Changes to subscription: http://mail.asis.org/mailman/listinfo/sigia-l
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.