Thursday, 4 March 2010 08:09 by
jlorimer
OK everyone hates them (complex passwords), but there is a compelling story I want to tell about a client that decided not to do it. Public servers, specifically mail servers are constantly being probed for logins. Simple passwords are broken easily. In this clients case one users account was broken into. Without even knowing it that username and password was then spread around the world. When we were alerted to the problem there was 58,000 spam emails in the outbound queues marked for sending. All because complex passwords were not required. This client will also be internet blacklisted for a while because of the volume of spam they were spewing just because of a simple password. So the moral of the story is make yourself protected by using complex passwords. The password should not look like a real word. Complex passwords should have a minimum of 8 characters. Those 8 characters should be random uper case, lower case, numbers and at least one symbol. We use a tool called passutils from PC Tools to generate passwords. It creates good secure complex passwords that would make breakins like described above very very rare. Kind of makes me wonder about online banking services where maximum of 7 characters is mandated and complexity is not required. How safe is your bank account
Be the first to rate this post
- Currently 0/5 Stars.
- 1
- 2
- 3
- 4
- 5
Thursday, 4 March 2010 08:09 by
jlorimer
OK everyone hates them (complex passwords), but there is a compelling story I want to tell about a client that decided not to do it. Public servers, specifically mail servers are constantly being probed for logins. Simple passwords are broken easily. In this clients case one users account was broken into. Without even knowing it that username and password was then spread around the world. When we were alerted to the problem there was 58,000 spam emails in the outbound queues marked for sending. All because complex passwords were not required. This client will also be internet blacklisted for a while because of the volume of spam they were spewing just because of a simple password. So the moral of the story is make yourself protected by using complex passwords. The password should not look like a real word. Complex passwords should have a minimum of 8 characters. Those 8 characters should be random uper case, lower case, numbers and at least one symbol. We use a tool called passutils from PC Tools to generate passwords. It creates good secure complex passwords that would make breakins like described above very very rare.
Be the first to rate this post
- Currently 0/5 Stars.
- 1
- 2
- 3
- 4
- 5