« It’s 10 O'Clock - Do You Know Where Your Information Is? | Main | Security Shock »

All Hail the Lowly Password

A recent Computerworld article by Todd Weiss, reinforces a basiic fact – that weak passwords make life easy for hackers. What he also mentions, and is not as obvious to many administrators, is the number of password attempts that are made on their servers.

Unless you monitor what is going on computers, you could be living in blissful ignorance.

Almost every machine which accepts connections is challenged many times each day and although there are many things you can do to protect your machines, the lowly password is an effective line of defense.

The author’s suggestion of an eight digit password using random letters, numbers and special characters is borne out by our own experience cracking passwords in our forensics lab. Dictionary, slightly modified dictionary, and shorter passwords are routinely cracked in minutes. Since technology advances quickly, we routinely use several more digits in our own servers.

Defense in depth is the best approach in protecting your machines. But as you pursue sophisticated defenses, don’t ignore the lowly password. Establish and enforce a password policy.

TrackBack

TrackBack URL for this entry:
http://zorg.webthis.net/MT/mt-tb.cgi/11

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on February 7, 2007 10:43 AM.

The previous post in this blog was It’s 10 O'Clock - Do You Know Where Your Information Is?.

The next post in this blog is Security Shock.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type 3.33