Slashdot Mirror


Write Down Your Passwords

joeykiller writes "Microsoft's senior program manager for security policy, Jesper Johansson, presents a provocative but interesting view on password policy: He claims that prohibiting users from writing down their passwords is bad for security. His main point is that if users are prohibited from writing down their passwords, they will use the same easy to guess password everywhere." From the article: "Since not all systems allow good passwords, I am going to pick a really crappy one, use it everywhere and never change it...If I write them down and then protect the piece of paper--or whatever it is I wrote them down on--there is nothing wrong with that. That allows us to remember more passwords and better passwords."

33 of 633 comments (clear)

  1. So Pen&Paper's the new replacement for Passpor by team99parody · · Score: 4, Funny

    Now we know what's replacing Microsoft Passport in Longhorn - pen&paper!

  2. And I'll keep it under my keyboard... by beorach · · Score: 2, Funny

    with my bank name and account number next to it..

    1. Re:And I'll keep it under my keyboard... by dodald · · Score: 5, Funny

      I have a single post it note under my keyboard that reads "9uL1i613".

      --
      101010b 2Ah 52o
    2. Re:And I'll keep it under my keyboard... by justforaday · · Score: 2, Funny

      I have a single post it note under my keyboard that reads "9uL1i613".

      mine says "password"

      --
      I'll turn into a supernova and burn up everything. Well I'll turn into a black little hole and you'll turn into string.
    3. Re:And I'll keep it under my keyboard... by camkind · · Score: 2, Funny

      mine says "This side down"

  3. Ok. by cmburns69 · · Score: 4, Funny

    Ok, here they are:

    Slashdot password: 12345
    Personal site password: 12345
    Bank account password: 12345

    Now my password is even more secure! Yay!

    --
    Online Starcraft RPG? At
    Dietary fiber is like asynchronous IO-- Non-blocking!
    1. Re:Ok. by fembots · · Score: 2, Funny

      Now my password is even more secure!

      So true, by open-sourcing your password, you don't need to worry about security anymore.

    2. Re:Ok. by ClownsScareMe · · Score: 2, Funny

      This joke is sooooo obvious. I though of it, I just didn't post it.

      --
      I read Slashdot for the articles
  4. One Word: by DrunkenTerror · · Score: 5, Funny

    Tattoos.

    1. Re:One Word: by Durinthal · · Score: 5, Funny

      Particularly in a private region. That way no geek would ever have to worry about someone else seeing it!

    2. Re:One Word: by fbform · · Score: 2, Funny
      Particularly in a private region.

      That's not how one does private key encryption.

      --
      Time flies like an arrow. Fruit flies like a banana.
  5. Wow... by MrByte420 · · Score: 5, Funny

    I've got the same combonation on my luggage!
    (sorry sorry sorry!)

    --
    If religous zealots don't believe in Evolution, then why are they so worried about bird flu?
  6. Re:I'll buy that piece of paper with some chocolat by Fulcrum+of+Evil · · Score: 2, Funny

    My password vault happens to be Firefox, though.

    How do you get your passwords out?

    --
    "We returned the General to El Salvador, or maybe Guatemala, it's difficult to tell from 10,000 feet"
  7. True story by HaeMaker · · Score: 3, Funny

    I'm a SysAdmin and at one place I worked, I noticed someone had written 'aaaaa' on their monitor. They wern't at their desk at the time, so I sat down, hit ctrl-alt-del and typed 'aaaaa' into the password field...

    1. Re:True story by sconeu · · Score: 3, Funny

      I refuse to play your chinese food mindgames!

      --
      General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    2. Re:True story by gregfortune · · Score: 2, Funny

      Heh, I've got a password on a post it note attached to my monitor. It's something like P43F^ss2Bn. I always wonder how many times people try it.

  8. Exactly right. . . by Sialagogue · · Score: 5, Funny

    This is the exact reason that I write all my passwords on post-it notes and stick them to my monitor.

    I have a 21-inch tube monitor and it weighs like 80 pounds, so nobody could even get it out the door much less steal it, so my passwords are going nowhere.

    --
    The only acceptable defense of scientific results is to say that they were the product of the Scientific Method.
  9. Re:So Pen&Paper's the new replacement for Pass by coop0030 · · Score: 2, Funny

    Maybe it's the new trend.

    Maybe pen&paper AD&D will be cool again!

  10. Re:So Pen&Paper's the new replacement for Pass by DaltonRS · · Score: 2, Funny

    And of course, they(M$) will introduce the following security initiative when pen and paper security protocols show evidence of security lapses. White-Out.

  11. Re:Passwords suck: simple solution: by xAXISx · · Score: 2, Funny

    You misspelled right wing scare tactic.

  12. Re:So Pen&Paper's the new replacement for Pass by irm · · Score: 2, Funny

    I've always written down my passwords. You just have make sure to keep them on the top of the Mountain of Despair, beyond the River of Doom. Total security!

  13. Re:So Pen&Paper's the new replacement for Pass by Anonymous Coward · · Score: 1, Funny
    I can see what's next.
    • Oil Paints replacing Microsoft Paint in Longhorn
    • A printed dictionary replacing Word's spell checker.
    Perhaps Longhorn really will revolutionize the computng industry.
  14. I can just see this... by Em+Ellel · · Score: 5, Funny

    For example, I'm only reading Slashdot from this particular computer, and I'm using a IBM E94 monitor, and there is this Sellotape dispenser on my desk with 1531 written on it. So my Slashdot password can be easily remembered as IBM!1531@E94#, or simply ibm1531e94 for those systems that cannot accept special characters.

    I can just see the following request to helpdesk:

    Please reset my password as someone borrowed my Sellotape dispenser and I can no longer log in.

    -Em

    --
    RelevantElephants: A Somatic WebComic...
  15. Re:Pseudo-Written Password by Anonymous Coward · · Score: 1, Funny

    I used to use a password-generation "method" which was to create a rather rude anagram about the particular user (with the appropriate number/symbol substitutions for letters, as necessary). After a couple of years of odd passwords one of the engineers finally started to catch on (it didn't help that he could sometimes hear me laughing while creating new-user passwords...).

  16. Re:So Pen&Paper's the new replacement for Pass by PakProtector · · Score: 4, Funny

    I should expect that kind of talk coming from a young, low uid person like yourself. You kids don't know how good you have it these days. Fancy computer graphics and a machine to keep track of details for you, letting you have your 'action' in 'real time.' Back in my day, we had cardboard cutouts, if we were lucky! Most of us used hand made lead figures that we had to paint by hand! And it could take hours just to do one massive battle because we had to do everything ourselves! In the snow! In our parent's basements! Pssh. You young people these days. I don't want your opinion until your UID is in the lower 50% of the population. PSssh. Kids. Think they know everything. In my day, we were lucky if we knew nothing! You were lucky just to not be a negative container of knowledge, sucking it out of other people until everyone knew nothing. Pssh. Kids.

    --

    Edward@Tomato - /home/Edward/ man woman
    man: no entry for woman in the manual.
    "Qua!?"

  17. Re:Don't treat it like cash by Amoeba · · Score: 4, Funny
    So if Jackson is on the $20 bill, what do 5 Jacksons make?


    The world's most dysfunctional family?

    --
    Do not taunt Happy-Fun Ball
  18. Re:No! by FirstTimeCaller · · Score: 4, Funny

    Why put the list in cyberspace at all? That's the beauty of paper, nobody online can steal a sheet of paper sitting in your home/office/dorm/loft/cave.

    But I thought you said not to put it on your machine at all!?!?! So what the heck is it doing under your home directory? :-)

    --
    Wanted: witty unique signature. Must be willing to relocate.
  19. Re:Pseudo-Written Password by Erik+Fish · · Score: 5, Funny

    If they take the Sellotape then you just set the building on fire.

  20. Re:The worst Slashdot password by kakos · · Score: 2, Funny

    Most systems don't allow empty passwords.

  21. Re:Bruce Schneier agrees by Penguinshit · · Score: 2, Funny


    One password to rule them all
    One password to find them
    One password to bring them all
    And in the darkness bind them.

  22. Liar. by apparently · · Score: 2, Funny

    So my Slashdot password can be easily remembered as IBM!1531@E94# Tried that, and got: "Danger, Will Robinson! You didn't log in! You apparently put in the wrong password, or the wrong nickname. Either try again, or have your password mailed to you if you forgot your password." Please advise.

  23. Don't misunderestimate people ;-) by Venner · · Score: 2, Funny
    Why put the list in cyberspace at all? That's the beauty of paper, nobody online can steal a sheet of paper sitting in your home/office/dorm/loft/cave.


    Not necessarily :) I used to know someone who had a webcam in their office. It was one of those geeky "things to do" at the time. He had controls to pan & zoom, control the a small light, etc, on his website.

    One day, I zoomed in on a piece of paper on the corner of his desk. Some rotation & sharpening in photoshop* revealed an IP and the word "gizzards8524". I telnetted** to the IP, tried his usual nickname and that word as the password and bingo - I was in.

    He was quite startled when a he got a console chat invitation from...himself. :)

    *as opposed to hollywood's ideas of image restoration that boggle the mind and break the laws of physics.

    **ssh wasn't popular yet.
    --
    A preposition is a terrible thing to end a sentence with.
  24. Re:Pseudo-Written Password by Anonymous Coward · · Score: 1, Funny

    Sorry, we had to replace your monitor while you were out last week. Someone accidentally drenched it with Coke. As a consolation we got you a much nicer monitor and also replaced your dingy old tape dispenser.

    What do you mean that keeps you from logging in? Don't be ridiculous.