Title: 'IT's locked me out!' Dealing with mandated password change Post by: HCK on December 01, 2014, 03:00:20 pm 'IT's locked me out!' Dealing with mandated password change
<article> <section class="page"> <p> A reader who wishes to remain anonymous has a bone to pick with corporate IT. He writes:</p>
<p> Depending on how open your IT department is to new ideas, you might forward them a copy of Microsoft’s So Long, And No Thanks for the Externalities: The Rational Rejection of Security Advice by Users (https://drive.google.com/viewerng/viewer?url=http://research.microsoft.com/en-us/um/people/cormac/papers/2009/SoLongAndNoThanks.pdf). It and other security studies suggest that the “best practice” of changing passwords every couple of months has outlived its usefulness. Not only are attacks more varied and swift than when these policies were put in place, but it often causes users the kind of frustration that leads to greater security lapses (taping their new password to the monitor or simply creating a single-character variation from the old password, for example).</p><p class="jumpTag"><a href="/article/2853496/its-locked-me-out-dealing-with-mandated-password-change.html#jump">To read this article in full or to leave a comment, please click here[/url]</p></section></article> Source: 'IT's locked me out!' Dealing with mandated password change (http://www.macworld.com/article/2853496/its-locked-me-out-dealing-with-mandated-password-change.html#tk.rss_all) |