Re: Restricted password useage



Good stuff. I was at Redmond last winter where he gave his talk on
passwords and pass phrases. The use of rainbow tables have made cracking of
shorter passwords fairly trivial though there is not enough storage to
create rainbow tables with all the possibilities for 20 character passwords
and pass phrases are just easier to remember. --- Steve MVP Windows
Security


"Mark Heitbrink [MVP]" <spam-only@xxxxxxxxxxxxxxxxxxxxx> wrote in message
news:eQSqaGkoFHA.764@xxxxxxxxxxxxxxxxxxxxxxx
> Steven L Umbach schrieb:
>> Otherwise consider enforcing long passwords such as a minimum of 15
>> characters and training your users to think pass phrases instead of
>> passwords. For instance " I forget my stupid password " [...]
>
> There is a good article about the discussion of using passwords
> or passphrases, from Jesper M. Johansson.
> http://www.microsoft.com/technet/security/secnews/articles/itproviewpoint091004.mspx
> http://www.microsoft.com/technet/security/secnews/articles/itproviewpoint100504.mspx
> http://www.microsoft.com/technet/community/columns/secmgmt/sm1204.mspx
>
> Mark
> --
> Mark Heitbrink - MVP Windows Server
> Homepage: www.gruppenrichtlinien.de
> W2K FAQ : http://w2k-faq.ebend.de
> PM: Vorname@Homepage, Versende-Adresse wird nicht abgerufen.


.



Relevant Pages

  • Re: Should be in crypto for criminals Re: just stupid?
    ... memorising pass phrases is not necessary. ... >> people to write down their passwords. ... words, not the same word, not even a human language. ...
    (sci.crypt)
  • Re: Expire or not expire?
    ... I don't force password changes, ... I prefer to force long pass phrases and let people select their own pass phrases. ... We also set the lockout policy so that an intruder could only brute force attempt about 100 passwords in an hour. ...
    (microsoft.public.security)
  • Re: Strong Passwords Revisited
    ... If you control logical and physical access to the repository of stored ... passwords, AND implement failed attmept lockout, it's not ... > I tell my people the best passwords are acronyms of phrases that mean ... >> is not far short of the possibilities with choosing 8 completely random ...
    (comp.os.ms-windows.nt.admin.security)
  • Re: Strong Passwords Revisited
    ... If you control logical and physical access to the repository of stored ... passwords, AND implement failed attmept lockout, it's not ... > I tell my people the best passwords are acronyms of phrases that mean ... >> is not far short of the possibilities with choosing 8 completely random ...
    (microsoft.public.win2000.security)
  • Re: Strong Passwords Revisited
    ... If you control logical and physical access to the repository of stored ... passwords, AND implement failed attmept lockout, it's not ... > I tell my people the best passwords are acronyms of phrases that mean ... >> is not far short of the possibilities with choosing 8 completely random ...
    (comp.security.misc)