How strict are your company on passwords?

Got something to say or just want fewer pesky ads? Join us... 😊



I'm not happy about this. Our company are changing the password requirements and I have to be on site while they do it. I'm waving my balls goodbye as they are going to be chewed off.

Here are the rules and suggestions for choosing a password. (Tony Le Mesmer - take note!)

The highlights of the new password policy include:
• Your Windows logon password will expire every 60 days.
• Passwords must contain eight characters or more.
• Passwords must contain 3 of the 4 security attributes. These attributes include:-
o English uppercase characters (A through Z)
o English lowercase characters (a through z)
o Numeric characters (0 through 9)
o Non-alphabetic characters (for example, !, &, #, %)
• Do not use significant portions of your name or logon name.
• A record of the previous 6 passwords will restrict using the same password again.
Some helpful hints and examples
The following hints and examples may provide some guidance towards creating that complex password that is easy for you to remember. All the following use lower case which counts as one of the 4 rules of complexity

Example 1 – The avid chess player.

Word Made into a complex password Hints
Checkmate cHeckmate1

Move the capital letter around – it does not always have to be the first letter
czechMate1
cheQuemate1 Substitute words which sound similar
ch3Quemate Substitute numbers or symbols for letters eg
@ = A
1 = L
3 = E
5 = S
6 = G
8 = B
0 = O

cHequeM8 Use TXT language if it is familiar to you
cZech%mate Use symbols to break up the word





Does anyone elses company demand this kind of password?
 






beorhthelm

A. Virgo, Football Genius
Jul 21, 2003
36,031
mine certianly doesnt, no password policy and worker frequently give their password to team members. Now while that is the sublime, yours is the ridiculous and will simply lead to people writing the password down.
 


Bluejuice

Lazy as a rug on Valium
Sep 2, 2004
8,270
The free state of Kemp Town
That's f***ing ludicrous.

I get wound up enough that I have to change my password every 30 days and it can't be the same as any of the previous 10. It just means that I invariably end up having to have IT reset once every few months as I don't remember it.

There's f*** all anybody could do even if they did know my log on password, except perhaps print off malicious word documents with a company letterhead. But does this really pose a security threat?

It just sounds like more hassle than it's worth to me TGC. IT are going to be inundated with calls about forgotten passwords, or otherwise people are just going to post-it their passwords to their computers rendering them essentially pointless anyway.
 


Bluejuice said:
That's f***ing ludicrous.

I get wound up enough that I have to change my password every 30 days and it can't be the same as any of the previous 10. It just means that I invariably end up having to have IT reset once every few months as I don't remember it.

There's f*** all anybody could do even if they did know my log on password, except perhaps print off malicious word documents with a company letterhead. But does this really pose a security threat?

It just sounds like more hassle than it's worth to me TGC. IT are going to be inundated with calls about forgotten passwords, or otherwise people are just going to post-it their passwords to their computers rendering them essentially pointless anyway.

You are preaching to the choir! This decision was made by ICT Governance - I would imagine the name would give away their role! They should be the ones on site when people have to change to this system - not us poor plebs. They also told people they could only use the Internet for 20 minutes a day before having their activity monitored. Now most of these people are auditing local councils and need access to their websites a lot of the time. But the grief I got over that will pale into significance when this little baby gets brought in.
 




JJ McClure

Go Jags
Jul 7, 2003
11,112
Hassocks
Our have to be a minimum of 6 characters but other than that they can be what ever you want.
 


Marshy

Well-known member
Jul 6, 2003
19,956
FRUIT OF THE BLOOM
its called security !.

Mine change every 30 days and i have probably 6 different log ons and passwords for different computer systems we access...
:(
 






Jul 20, 2003
20,705
a few years ago I was working for a small company and a few of us were concerned about what was going on. we decided to try and access the directors PC.

second attempt at the password and we were in, it was the name of his dog
 


My companies deafult password is, ermmmm password.

And we can't change it because the securities they have set up on the accounts don't allow us to as we don't have admin rights.

You have to call help desk and ask them to change it for you.
 






Wardy

NSC's Benefits Guru
Oct 9, 2003
11,219
In front of the PC
We have a number of systems all of which have there own requirment. The basic NT password, needs to be 6-12 characters long and needs to be chanegd every 30 days.

Other systems have blocked words and are changed every 28 days. Not as bad as yours though.
 








Da Man Clay

T'Blades
Dec 16, 2004
16,286
I work for the old bill and are password restrictions aren't like that! Its just got to have a number in it somewhere!
 




binky

Active member
Aug 9, 2005
632
Hove
I have 9 passwords for different parts of the windows/network/systems/email/web etc that I use as part of my work.
All of them have to change every calendar month.
All of them follow the security rules you laid out in the initial post.

On "password day", I spend around an hour logging on to all the systems, changing and verifying the password.

Do I write all the passwords down. Of course not :lolol:
 


Grendel

New member
Jul 28, 2005
3,251
Seaford
The Great Cornholio said:


The highlights of the new password policy include:
• Your Windows logon password will expire every 60 days.
• Passwords must contain eight characters or more.
• Passwords must contain 3 of the 4 security attributes. These attributes include:-
o English uppercase characters (A through Z)
o English lowercase characters (a through z)
o Numeric characters (0 through 9)
o Non-alphabetic characters (for example, !, &, #, %)
• Do not use significant portions of your name or logon name.
• A record of the previous 6 passwords will restrict using the same password again.

All of the above for Windows logon & database logon. Also have to change the phone password every 60 days.
 




Blackadder

Brighton Bhuna Boy
Jul 6, 2003
16,122
Haywards Heath
I could tell you our password policy but then I'd have to kill you!
 


Highfields Seagull

Well-known member
Jul 7, 2003
1,448
Bullock Smithy
The Great Cornholio said:
You are preaching to the choir! This decision was made by ICT Governance - I would imagine the name would give away their role! They should be the ones on site when people have to change to this system - not us poor plebs. They also told people they could only use the Internet for 20 minutes a day before having their activity monitored. Now most of these people are auditing local councils and need access to their websites a lot of the time. But the grief I got over that will pale into significance when this little baby gets brought in.

I think I work for the same people as you TGC.
 


Albion and Premier League latest from Sky Sports


Top