LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 12-14-2017, 10:52 AM   #1
svetlanarosemond
LQ Newbie
 
Registered: Nov 2017
Posts: 14

Rep: Reputation: Disabled
Reaction to Password Policy


When the topic of computers comes up between friends/family, the topic of security is not too far behind, and I always mention I use KeePass in addition to long and complex passwords. I'm often met with laughs and the absurd question of Why?

Does this happen to you?

I don't understand the humor in having strong passwords. I, as an end user of certain online services can only do so much to protect my accounts, one of which is, have a long and complex password. The service also has the responsibility of storing those passwords in a secure way, however, we all know sometimes this isn't the case.

Last edited by svetlanarosemond; 12-14-2017 at 11:47 AM.
 
Old 12-14-2017, 10:56 AM   #2
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,482

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
Quote:
Originally Posted by svetlanarosemond View Post
Does this happen to you?
Sometimes. I also have a family member that keeps all their passwords in a file passwords.doc on the desktop of their laptop. And the password to the laptop is kept in a book with "passwords" on the front, in the computer cabinet beside the desktop PC.
 
Old 12-14-2017, 11:38 AM   #3
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,673
Blog Entries: 4

Rep: Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945
My parents do the same thing, and, as long as the passwords aren't kept on the computer and no one breaks into the house, it's actually not an insecure strategy to keep them in a paper notebook.

Failing that, a "secure keychain" tool is another good way to do it. "PasswordSafe" is very nice if you need to transport keychain-lists among multiple platforms.

I don't think that an "incomprehensible" password is necessarily any more secure than any other. nougat7upstairs is quite a reasonable value as long as you can reasonably control access to the target. And that's where I routinely put OpenVPN, with secure digital certificates, on my front-line. To even reach any service which would allow a password to be entered, you must pass through a cryptographic portcullis that an outsider cannot even detect.
 
Old 12-14-2017, 12:43 PM   #4
Sefyir
Member
 
Registered: Mar 2015
Distribution: Linux Mint
Posts: 634

Rep: Reputation: 316Reputation: 316Reputation: 316Reputation: 316
I typically say I don't have to worry anymore about remembering different passwords. And when Yahoo (or something else) gets hacked (again), I only have to change that one instead of all of them and then worrying about making another password I'll remember but will probably forget.
I just have to remember one password.
 
Old 12-14-2017, 03:50 PM   #5
dave@burn-it.co.uk
Member
 
Registered: Sep 2011
Distribution: Puppy
Posts: 601

Rep: Reputation: 172Reputation: 172
I have a different pasword for every site I visit and don't store any of them.
 
Old 12-14-2017, 04:26 PM   #6
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
https://www.sans.org/reading-room/wh...-tutorial-1636

Easy complex passwords.
 
Old 12-15-2017, 09:25 AM   #7
cynwulf
Senior Member
 
Registered: Apr 2005
Posts: 2,727

Rep: Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367Reputation: 2367
Quote:
Originally Posted by svetlanarosemond View Post
I'm often met with laughs and the absurd question of Why?
This is not really a question of passwords - it's the whole problem of computing security and that the majority of people in general don't care about it, or assume that someone else takes care of it on their behalf.

There's also the culture that if you're someone who concerns themselves with security/privacy, that you're somehow paranoid, etc.

Until that changes, worrying about and issuing directives or advice on password complexity is futile.

Last edited by cynwulf; 12-15-2017 at 09:26 AM.
 
Old 12-15-2017, 11:01 AM   #8
vmccord
Member
 
Registered: Jun 2012
Location: Topeka, KS
Distribution: Mostly AWS
Posts: 71
Blog Entries: 31

Rep: Reputation: Disabled
Because loss can be insured for, most people are comfortable with substantial risk.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Configure my Redhat directory server password policy and account lockout policy arunplanet Linux - Newbie 4 10-06-2012 08:59 AM
How to set the password policy and lockout policy bin_shell Linux - Security 4 03-24-2010 03:30 PM
Password policy Bharat Kumar pankaj Linux - Server 1 08-17-2008 01:47 AM
Password policy sunhui Linux - Software 2 05-12-2006 03:19 AM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 10:07 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration