funsec mailing list archives

Re: (Yet Another) Lost Ernst & Young Laptop Exposes IBM Staff


From: Drsolly <drsollyp () drsolly com>
Date: Thu, 16 Mar 2006 20:14:06 +0000 (GMT)

It's like the "never write passwords down" mantra 

I've been telling people to ignore that for 20 years.

- which is more secure,
my using a weak password I can remember on a server, or me using a strong
password I have written down in my wallet?
 
It's worse than that. 

People now have dozens of passwords. 

So, they try to make them all the same, which means that when one is 
compromised, they all are.

And they *do* get compromised. Joe Lunchbox uses the same password when he 
logs into his favourite Steam Railway fun site as when the logs into his 
bank, because it's been impressed on him that he shaouldn't write his 
password down. But no-one told him not to use the same password on 
everything he uses.

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: