Re: Recovery via Unrecovery
- From: chris+news@xxxxxxxxxxxxx (Chris Suslowicz)
- Date: Mon, 27 Aug 2007 22:51:57 +0100
In article <favc9o$if0$1@xxxxxxxxxxxxxxxxxxxx>,
dj3vande@xxxxxxxxxxxxxxxxxxx (Dave Vandervies) wrote:
I once had an automated password strength checking system reject a
password that I had created with a pair of 8-sided dice and a lookup
table containing upper and lower case letters, decimal digits, and two
punctuation symbols. Something about a run of alphabetic characters
being too long.
MikeA, avert your eyes, please!
Or the recent upgrade to PN-NPS2 on one of the dinosaurs that introduced
a default "*NO* repeated letters permitted" rule.
I was Not Impressed. If the next one had been rejected as well, I would
have gone to the people who decreed the policy with a complaint along
the lines of "I give up, what IS the password I'm allowed to use?".
If you make the password rules /too/ Byzantine, people just start writing
the passwords on post-it notes.
I used to write my passwords down: 9 pairs of 6-sided dice throws. First
pair picks the lookup table. (Generated by sequentially filling a 6x6 grid
with the ($Security System permitted) characters picked out of a hat. I
think I omitted $CurrencySymbol to avoid codepage problems, and there
were always a couple of characters left in the hat after filling the table.
6 pages, 6 tables per page, generated during a long train journey when
I ran out of books to read.) Remaining 8 pairs index into that table.
Final sanity check (shuffle letters if it hits certain rules) and then
write the number down before changing the password.
There's /a/ system which requires a physical dongle, an RSA token, *AND*
a 14-digit password (mixed case, alphanumeric + specials) at Ork which I
thankfully don't have to use....
Chris.
--
Service with a capital "Bugger Off".
.
- Follow-Ups:
- Re: Recovery via Unrecovery
- From: Dave
- Re: Recovery via Unrecovery
- From: Peter H. Coffin
- Re: Recovery via Unrecovery
- From: Mike Andrews
- Re: Recovery via Unrecovery
- References:
- Recovery via Unrecovery
- From: Jay Chandler
- Re: Recovery via Unrecovery
- From: Alan J Rosenthal
- Re: Recovery via Unrecovery
- From: David Gallatin
- Re: Recovery via Unrecovery
- From: Zebee Johnstone
- Re: Recovery via Unrecovery
- From: Dave Vandervies
- Recovery via Unrecovery
- Prev by Date: Re: Failover succeeds, again, and again, and again.
- Next by Date: Re: Recovery by mailing list
- Previous by thread: Re: Recovery via Unrecovery
- Next by thread: Re: Recovery via Unrecovery
- Index(es):
Relevant Pages
|
Loading