Re: No lockout policy... why not?
- From: "Anna Clark" <anna.clark(no spam)@verizon.net>
- Date: Tue, 1 May 2007 19:40:00 -0400
Hi Everyone:
While I will agree with all of the above about lockouts and strong passwords
and all the rest, it seems to me that the ultimate vunerabilty in this
senerio is the administrators password.
Unless I have missed something, you can't disable it, you can't lock it out,
and while you can "re label/rename" it, the underlying account is still
there and known to the bad guys.
Seems to me that if one is really concerned about this level of security,
the policy advocated by Leythos and others of having a device in front of
your server(s) that logs and requires authentication is the best one.
Please tell me I have it confused. :-)
Anna Clark
"kj" <kj@xxxxxxxxxxx> wrote in message
news:ux6OiYDjHHA.1260@xxxxxxxxxxxxxxxxxxxxxxx
Dave Nickason [SBS MVP] wrote:
In big organizations, lockout is a prime cause of help desk calls, so
enterprises have a huge cost associated with it. That's the only
valid reason I've ever heard for not using it, and IMO it doesn't
really apply in small businesses. I've always had a lockout policy,
and I only remember one lockout in the last probably 6-7 years.
Some over zealous security minded person try's to implement a policy like
they would on a mainframe without really understanding the Windows C/S
environment.
Lockout policy should deter and delay password cracking attempts and alert
administrators to the activities. It shouldn't lock out the user who
forgets his password. Afterall, how many are going to suddenly remember
the password before calling the help desk or administrator anyway?
It's not going to happen. It's forgot, it needs a reset, and lockout
wouldn't matter anyway, it's a help desk call.
On the other hand, if you are allowed to "guess" as often and as many
times as you like, eventually you'll get in.
--
/kj
.
- Follow-Ups:
- Re: No lockout policy... why not?
- From: kj
- Re: No lockout policy... why not?
- References:
- Re: No lockout policy... why not?
- From: kj
- Re: No lockout policy... why not?
- From: Dave Nickason [SBS MVP]
- Re: No lockout policy... why not?
- From: kj
- Re: No lockout policy... why not?
- Prev by Date: Re: Sophos Anti-Virus SBE problems
- Next by Date: Re: No lockout policy... why not?
- Previous by thread: Re: No lockout policy... why not?
- Next by thread: Re: No lockout policy... why not?
- Index(es):
Relevant Pages
|