09-23-04 02:21 AM
[Stefaan A Eeckels]:
>
> It's one of the reasons I'm always advising against using set
> rules to derive user names (things like the first five characters
> of the surname and the first three characters of the first
> name). You'd be amazed how often the password is the user's first
> name or surname, or their initials with the date of birth, etc.
oh come on, you need to enforce a modicum of rules for passwords!
we have many rules, like "no dates", "can't use only lower case
letters", "can't include own name", "can't use dictionary words"
etc. etc. we also regularily run John the Ripper on our password
file, although I'm happy to say it rarely cracks many passwords.
(with 65k accounts, you'll have to expect a few.) users are required
to change their password at least once per year.
--
Kjetil T.
[ Post a follow-up to this message ]
|