22/11/2011

"Don't tell anyone this, but it's..."

I heard this, this morning, followed by an explicit set of instructions how to spell the password in question. I'd got the username as well.

Couple of thoughts:
- You should not need to give users an admin password EVER. Give them an admin account local to the machine and then they are responsible for it.
- Don't assume that just because you're in a different country, someone won't understand your language.
- Admin passwords should not be simple enough to explain in terms of words (the password in question was laughably weak).
- If you need to administer lots of passwords, then use a password tool. Examples include password safe or keepass, both of which are cross-platform. Choose a decent passphrase!

- Bret

No comments:

Post a Comment