<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Eddie Awad’s Blog - Latest Comments in Top ten tips for better password management</title><link>http://awads.disqus.com/</link><description>News, views, tips and tricks on Oracle and other fun stuff</description><atom:link href="https://awads.disqus.com/top_ten_tips_for_better_password_management/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Mon, 28 Jul 2008 18:52:08 -0000</lastBuildDate><item><title>Re: Top ten tips for better password management</title><link>http://awads.net/wp/2006/05/16/top-ten-tips-for-better-password-management/#comment-3658576</link><description>&lt;p&gt;Good points Marvin.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Eddie Awad</dc:creator><pubDate>Mon, 28 Jul 2008 18:52:08 -0000</pubDate></item><item><title>Re: Top ten tips for better password management</title><link>http://awads.net/wp/2006/05/16/top-ten-tips-for-better-password-management/#comment-3658575</link><description>&lt;p&gt;There is a fundamental problem with password security which is epitomised in these rules/tips, it assumes that users are normal people. They aren't! They have no idea of the work that is needed to recover from a password compromise attack, no knowledge of the risk to their business of data loss or theft, not a clue on what to do to limit the damage caused by an elecronic break in.&lt;/p&gt;&lt;p&gt;Why Should They? They are the users. That is what the Sysadmin does.&lt;/p&gt;&lt;p&gt;Thus I have a problem with tip 8. The automatic forcing of password changes every XX days is a bad practice. As is complexity management ie making people use very high complexity passwords on a regular changing cycle. If this is realy essential then companies should look for another method of security management such as CHAP or Biometrics. &lt;br&gt;Forcing users to change passwords every xx days increases the chance of weak paswords. High complexity password increases the chance of the passwords being written down.&lt;/p&gt;&lt;p&gt;A far better method of good password management is EDUCATION!!! teach users to use sensible good passwords. Work with the users to ensure that they chose sensible passwords that are secure, manageable and above all private.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Marvin</dc:creator><pubDate>Mon, 28 Jul 2008 07:17:10 -0000</pubDate></item><item><title>Re: Top ten tips for better password management</title><link>http://awads.net/wp/2006/05/16/top-ten-tips-for-better-password-management/#comment-3658574</link><description>&lt;p&gt;Password is very important. And it should not be stored in computer. There are many differenct passwords for me. It is hard to remmeber all. So what I do with the password. I converted my passwords into my own codes and write them down on my small book. Even someone see my book but they could not understand the codes.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">LookingSoftware</dc:creator><pubDate>Fri, 18 Apr 2008 10:32:56 -0000</pubDate></item><item><title>Re: Top ten tips for better password management</title><link>http://awads.net/wp/2006/05/16/top-ten-tips-for-better-password-management/#comment-3658573</link><description>&lt;p&gt;A bit agree, Mr Awads, but i think we should perform a 'small risk assessment first' into the area that consider as high security risk or lower security risk. The higher security risk need higher password management to.&lt;/p&gt;&lt;p&gt;For better passsword management using &lt;a href="http://passwordsafe.sourceforge.net/" rel="nofollow noopener" target="_blank" title="http://passwordsafe.sourceforge.net/"&gt;http://passwordsafe.sourcef...&lt;/a&gt; is recommended&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anjar Priandoyo</dc:creator><pubDate>Tue, 26 Feb 2008 22:13:01 -0000</pubDate></item><item><title>Re: Top ten tips for better password management</title><link>http://awads.net/wp/2006/05/16/top-ten-tips-for-better-password-management/#comment-3658572</link><description>&lt;p&gt;Regarding number 4, where I work, I am forced to change my Windows logon password every three months. This is more like &lt;i&gt;force &lt;/i&gt;than &lt;i&gt;foster&lt;/i&gt;. But I'm fine with it because it definitely is more secure that way. It is more hassle for me, but more secure for the company. After all, it's always a compromise.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Eddie Awad</dc:creator><pubDate>Wed, 17 May 2006 15:25:54 -0000</pubDate></item><item><title>Re: Top ten tips for better password management</title><link>http://awads.net/wp/2006/05/16/top-ten-tips-for-better-password-management/#comment-3658571</link><description>&lt;p&gt;All good advice, but a list of do's and don'ts is no way to "foster a culture" of anything - either users will take the advice on board or they will give up because it's all too difficult.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;The exceptions are tips #3 and #10, which are things the company needs to do to foster a culture of security. In lieu of #10, #9 is probably a necessity but even that will not foster a culture of secure password management.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jeff Kemp</dc:creator><pubDate>Wed, 17 May 2006 01:50:06 -0000</pubDate></item><item><title>Re: Top ten tips for better password management</title><link>http://awads.net/wp/2006/05/16/top-ten-tips-for-better-password-management/#comment-3658570</link><description>&lt;p&gt;areyoukidding, are you kidding me? You're free to store your passwords where ever you want, but I would never store my passwords in &lt;b&gt;plain text&lt;/b&gt; either on paper or in a file on a computer.&lt;/p&gt;&lt;p&gt;&lt;br&gt;&lt;/p&gt;&lt;p&gt;The main reason I use a software program to manage my passwords is because of &lt;b&gt;password encryption&lt;/b&gt;. So, even if someone gains access to my password file, that person will not be able to read my passwords.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Eddie Awad</dc:creator><pubDate>Tue, 16 May 2006 21:19:15 -0000</pubDate></item><item><title>Re: Top ten tips for better password management</title><link>http://awads.net/wp/2006/05/16/top-ten-tips-for-better-password-management/#comment-3658569</link><description>&lt;p&gt;With all the corruption we hear about these days between governments and software and web companies, I'm not so sure I'd trust storing all of my passwords in any sort of software.  I say, think pen and paper, write that shit down and lock it up.  If you can't remember one of your dozens of password be sure NOT to forget the combination to your safe and go look it up.   But I assure you, if you store your password in a file on your computer, someone, sometime or another will hack that shit.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">areyoukidding</dc:creator><pubDate>Tue, 16 May 2006 16:33:01 -0000</pubDate></item></channel></rss>