Giving Up Passwords For Chocolate
RonnyJ writes "The BBC is reporting that, according to a recent survey, more than 70% of people would willingly give up their computer password in exchange for as little as a bar of chocolate. Over a third of the people surveyed even gave out their password without having to be bribed, and most indicated that they were fed up with having to use passwords."
...at many of the places I've worked at is that the users have as many as a dozen passwords to remember for different systems, and each one expires at a different time and has different rules for how long and complex it has to be.
Most of them keep their passwords written down on a sheet of paper right on their desk.
try passwordsafe
http://sourceforge.net/projects/passwordsafe/
-
But if users don't like using password, why force them.
Because of all the extra vulnerabilities it exposes. If a malicious attacker gains access to their account the number of ways they can try to get root privledges grows. There are quite a few root exploits you have to have an account on the system to use. Besides, the passwords are for their protection too, from things such as the E-mail to the user's boss you mention to losing personal information. (I've seen users who stored their credit card account numbers in a plain text file for "convenience".) Basically sysadmins aren't just trying to protect the systems, but the users as well -- even if that means protecting them from their own idiocy.The key is to make them memorable, pronouncable non-words.
Reading a lot of science-fiction and fantasy books also helps much - especially when you can read them in some non-Western language. "Rohan" or "Alderan" will be too obvious, but "BalduryiBadubiny" won't be that easy to be crack by brute force - while it's very easy to memorize (and pronounce!) if you can read Stanislaw Lem in Polish.
Having volatile resources to protect, like disk quotas or print quotas, can help, but then you need to give users a fighting chance by providing constant education verbally and written as well has having a secure system. I suspect that one reason a lot of users don't take it seriously is that many (most) highly hyped "IT-Solutions" / E-Thneeds come across as Mickey Mouse.
Beta is broken and the link to classic doesn't work. Stop wasting our time or there won't be anybody left here.
When I upgraded from dial up to broadband, the monkey at the other end of the phone asked me if I knew what my password was... well, yes, obviously.
A few days later I received a letter confirming the upgrade, and lo-and-behold, they had felt the need to remind me what my password was. I'm not even sure if I like the fact that they can tell me what my password is but sending it through the post in plain text is just dumb.
I use one password for anything I don't really care about (/. login)
/. login isn't through SSL. So I wouldn't use the same password for /. as for Citibank, etc.
Correct me if I'm wrong, but
It's still interesting to see that in two years of cybercrime and media frenzies that nothing has really changed...
Do you or your partner snore? - Visit www.snoring.com.au
Hah, no, it means they are keeping your plain text password in a database somewhere, instead of only keeping an unreversible hash like they should.
I've had enough abrasive sigs. Kittens are cute and fuzzy.
Are the people who will not give their password, no matter what. As "the IT-guy" I require access to just about all computers here. And yes, that includes the end-user desktops/laptops. And there are some people here who simply refuse to give me the passwords to their system! Noooo, they have to type the password themselves. And that means I have to drag them from their meetings and such just so they can log in to their machine so I could work on it!
Hell, I have received maybe 200 passwords while working here, and I don't remember any of them. I don't keep them stored anywhere, and I don't have eidetic memory, so there's no risk. And still I hear the "I use the same password in several places, and I don't want to change all those passwords if I gave you my password!". If you are so careful when it comes to security, you shouldn't use the same password everywhere! And yes, you CAN give your password to the IT-department if they walk up to you and ask you for it. If you don't... well, we can always reset your password!
Sheesh, some people....
Lesbian Nazi Hookers Abducted by UFOs and Forced Into Weight Loss Programs - -all next week on Town Talk.
Fraternities are social organizations in college in the US. Some are coed and service oriented. What most people refer to, though, are all male and are mostly social in nature.
Fraternity secrets would involve the procedure of becoming a member, the rituals of the house, etc. Some houses are more secretive than others.
Watch Animal House or any other fraternity movie to get the general idea.
I have seen it done on three occasions, each time someone who has just fallen asleep ( cat/power napped ) at their desk.
I'd gladly give up my password to many sites for a bar of chocolate. I'd be getting a great deal. Heck, I'll tell you all now: it's "password"... or sometimes if the sites use a dictionary check, I'll go for "password1".
A whole lot of the places I visit protect absolutely nothing of significance to me with their password. As in, maybe I can select a color scheme for a site, or similar. And for a lot of those, I know perfectly well I'll never go back to a site; I just have to do a one-time transaction. Exactly how concerned am I supposed to be that "hackers" might change my color scheme on a news website. Actually, a lot are even worse than that--like commercial newspapers (NYT and friends): I can't even change a color scheme, they just insist on me giving them demographic info. But it's a one way thing, you can't see or change it after "registration." Even if crackers -could- change how old the NYT thinks I am, why do I care about that exacty?
Opinions of security are probably harmed by the overuse of security measures where there is self-evidently no reason to have them. Casual users get in the habit of thinking passwords are just a nuisance... even when the -do- something significant.
Buy Text Processing in Python