Page 3 of 3 FirstFirst 123
Results 33 to 41 of 41

Thread: Insane Security Policies

  1. #33
    Get in the van. Fraz's Avatar
    Join Date
    Aug 2007
    Location
    Bristol
    Posts
    2,919
    Thanks
    283
    Thanked
    396 times in 230 posts
    • Fraz's system
      • Motherboard:
      • Gigabyte X58A-UD5
      • CPU:
      • Watercooled i7-980X @ 4.2 GHz
      • Memory:
      • 24GB Crucial DDR3-1333
      • Storage:
      • 240 GB Vertex2E + 2 TB of Disk
      • Graphics card(s):
      • Water-cooled Sapphire 7970 @ 1175/1625
      • PSU:
      • Enermax Modu87+
      • Case:
      • Corsair 700D
      • Operating System:
      • Linux Mint 12 / Windows 7
      • Monitor(s):
      • Dell 30" 3008WFP and two Dell 24" 2412M
      • Internet:
      • Virgin Media 60 Mbps

    Re: Insane Security Policies

    Quote Originally Posted by TheAnimus View Post
    Once again no.

    Think how small the search space would be by the time you've worked out the constraints (ie there must be at least 4 keys to the left, one above, but only 2 below.... etc.
    Although technically correct, what you are saying means that whoever is trying to brute force crack the password knows that this is the scheme. This is highly unlikely to be the case.

    Besides, surely it's pretty obvious if someone is trying to brute-force an account... this is all bonkers.

  2. #34
    Huge Member Brucelles's Avatar
    Join Date
    Mar 2007
    Location
    Carcassonne
    Posts
    1,756
    Thanks
    56
    Thanked
    203 times in 101 posts
    • Brucelles's system
      • Motherboard:
      • Gigabyte GA-F2A78M-D3H
      • CPU:
      • AMD A8-6600K APU
      • Memory:
      • 16Gb DDR4 800
      • Storage:
      • 1Tb Samsung, 320 Gb no name I can recall, 500Gb Sandisk SDD
      • Graphics card(s):
      • PNY - XLR8 GeForce 8800GTS
      • PSU:
      • 550W Corsair
      • Case:
      • Zalman
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • Samsung S27C590H
      • Internet:
      • Orange Livebox Wireless ADSL - Sucks something rotten, and SFR Neuf box. Sucks less.

    Re: Insane Security Policies

    When I worked in Zurich I was with a major bank that has thousands of people and hundreds (literally) of systems. I still have my (paper) notebook from those days and I have a whole A4 page pretty much covered with three columns: System name, UID,
    PWD. So far, pretty poor. But then we changed from 3 monthly password changes to monthly and the notebook just goes apeshirt. There's no way a normal person can remember even 10 meaningless passwords.

    I suppose you could have the password list on the wall, with the knowledge that it would take ages to try out all of the pwd / uid combinations.

    (Thanks Evilmunky)
    Eagles may soar, but weasels never get sucked into jet intakes.

  3. #35
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: Insane Security Policies

    Quote Originally Posted by Fraz View Post
    Although technically correct, what you are saying means that whoever is trying to brute force crack the password knows that this is the scheme. This is highly unlikely to be the case.

    Besides, surely it's pretty obvious if someone is trying to brute-force an account... this is all bonkers.
    If the series is say 14 long, odds are the posistion could be narrowed down to ~4 ish starting points by my quick calculations (could use proper brownian motion to figure out the 'right' awnser, but I do have work to do , just as soon as the lump of **** that is infragistics will let me, damn GUI developement)

    All they need to know is the scheme. My point is, bloody long concatinations of real words are by far and away safer, when mixed with easy to remeber spellings and numbers.
    throw new ArgumentException (String, String, Exception)

  4. #36
    o|-< acrobat's Avatar
    Join Date
    May 2006
    Posts
    1,754
    Thanks
    225
    Thanked
    75 times in 58 posts
    • acrobat's system
      • Motherboard:
      • Gigabyte DS4 965p Revision 2
      • CPU:
      • E6600
      • Memory:
      • Corsair 4gig DDR 800 (C4)
      • Storage:
      • two 320gig Seagate Barracudas, and one 750 gig Seagate Barracuda (7200.10) and a 750gig same brand.
      • Graphics card(s):
      • 8800GTX
      • PSU:
      • Corsair HX 620
      • Case:
      • Akasa Eclipse 62
      • Monitor(s):
      • Apple Cinema Display 20"
      • Internet:
      • Virgin Media - Slow, expensive rip off, Indian customer service. Great choice eh? :C

    Re: Insane Security Policies

    Quote Originally Posted by Spanamana View Post
    I remember some years ago a large company (3000+ employees) upheld high levels of password security. One Monday morning the helpdesk staff had 40% of the users calling to get their passwords reset. These password resets had to be approved by their line management, who unfortunately were also locked out.

    The reason for the sudden dramatic increase in password resets was due to the users, being unable to remember their complex passwords, had scribbled their passwords on the wall near their desks. Unfortunately, over that particular weekend the offices had been redecorated.

    G
    hehe

  5. #37
    Mostly Me Lucio's Avatar
    Join Date
    Mar 2007
    Location
    Tring
    Posts
    5,163
    Thanks
    443
    Thanked
    445 times in 348 posts
    • Lucio's system
      • Motherboard:
      • Gigabyte GA-970A-UD3P
      • CPU:
      • AMD FX-6350 with Cooler Master Seldon 240
      • Memory:
      • 2x4GB Corsair DDR3 Vengeance
      • Storage:
      • 128GB Toshiba, 2.5" SSD, 1TB WD Blue WD10EZEX, 500GB Seagate Baracuda 7200.11
      • Graphics card(s):
      • Sapphire R9 270X 4GB
      • PSU:
      • 600W Silverstone Strider SST-ST60F
      • Case:
      • Cooler Master HAF XB
      • Operating System:
      • Windows 8.1 64Bit
      • Monitor(s):
      • Samsung 2032BW, 1680 x 1050
      • Internet:
      • 16Mb Plusnet

    Re: Insane Security Policies

    At least you have a security policy!

    The company I work for refuses to let me impliment a proper policy, atm all users have identical passwords that never, ever get changed....

  6. #38
    Senior Member
    Join Date
    Jul 2003
    Posts
    12,183
    Thanks
    910
    Thanked
    598 times in 419 posts

    Re: Insane Security Policies

    I know that feeling, once I get a bit of time I'm gonna sort out a proper policy here, I'm already on the hit list for blocking facebook/myspace etc.

    Had one girl that works here that was being rather suspicious with her PC useage, accidentally turned on her MSN chat log's and lets just say if we did have a policy she woulda been outta here. Had a word with her she said she'd stop, checked again a few days later and shes still at it, however she doesnt actually need the internet for her job here so she now has no internet access...

  7. #39
    Get in the van. Fraz's Avatar
    Join Date
    Aug 2007
    Location
    Bristol
    Posts
    2,919
    Thanks
    283
    Thanked
    396 times in 230 posts
    • Fraz's system
      • Motherboard:
      • Gigabyte X58A-UD5
      • CPU:
      • Watercooled i7-980X @ 4.2 GHz
      • Memory:
      • 24GB Crucial DDR3-1333
      • Storage:
      • 240 GB Vertex2E + 2 TB of Disk
      • Graphics card(s):
      • Water-cooled Sapphire 7970 @ 1175/1625
      • PSU:
      • Enermax Modu87+
      • Case:
      • Corsair 700D
      • Operating System:
      • Linux Mint 12 / Windows 7
      • Monitor(s):
      • Dell 30" 3008WFP and two Dell 24" 2412M
      • Internet:
      • Virgin Media 60 Mbps

    Re: Insane Security Policies

    Quote Originally Posted by Lucio View Post
    At least you have a security policy!

    The company I work for refuses to let me impliment a proper policy, atm all users have identical passwords that never, ever get changed....
    Don't suppose you work for a bank at all, do you?

  8. #40
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: Insane Security Policies

    thats bad news! whats the point in having passwords then? To be honest when I worked for the NHS it was like that as well.
    □ΞVΞ□

  9. #41
    Registered+
    Join Date
    Oct 2007
    Posts
    50
    Thanks
    5
    Thanked
    1 time in 1 post

    Re: Insane Security Policies

    Or you can just try and use your <insert name of store here> bonus card's number together with abit of improvisation.

    ie: 1234567MarksAndSpencers

Page 3 of 3 FirstFirst 123

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Firefox suffers first 'extremely critical' security hole
    By XA04 in forum General Discussion
    Replies: 18
    Last Post: 12-05-2005, 12:13 PM
  2. Have you done all of your windows updates ?
    By Moby-Dick in forum General Discussion
    Replies: 33
    Last Post: 05-05-2004, 01:23 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •