Announcement

Collapse
No announcement yet.

In which we force better security.

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • In which we force better security.

    So my company (3 companies in one actually...we're the triforce...or something.) has recently been hacked by a tech's insecure password. The CEO has always insisted security take a back burner to fitting more customers per server, until now.

    Last night, we rolled a change FORCING customers to change passwords, by setting a temporary password of random characters that is emailed to the email address on the account. The customer must log in using the password, then set a new password that adheres to the new limits: they must use 2 numbers, 1 capital letter, and at least 1 special character.

    Apparently this isn't a popular move among the same group of customers who always accuse us of having bad security when their sites get regularly hacked for having a password of 'password1234'.

    Fortunately, since I'm now a sysadmin, I don't have to talk to them any more, and I know all the techs resent and hate us as much as the customers who've flooded our phone trunks (it was so full at one time that customers were getting busy signals). Really feel sorry for the techs, and not so much the customers.
    Coworker: Distro of choice?
    Me: Gentoo.
    Coworker: Ahh. A Masochist. I thought so.

  • #2
    I never got anything emailed to me.
    Getting offended is a great way to avoid answering questions that make you sound dumb. - exmocaptainmoroni

    Comment


    • #3
      I hate hackers. Got my facebook (my fault I had a stupid easy password) and my WOW account hacked. That's good that you guys made it so they have to have harder passwords. I should've done that!

      Comment


      • #4
        It doesn't matter how hard the password is to guess, a lot of the time it'll be keyloggers taking the passwords
        MMO Addicts group

        Comment


        • #5
          I used to be good at "hacking"
          University required one uppercase letter, at least one symbol. at least six characters.
          Most people capitalized the first letter and used an ! at the end of it. I'm shocked nobody every guessed mine because it was insanely simple and followed the same mistakes I pointed out. and was a nickname everyone has called me by for years.
          I'm sorry reading is not a new concept it has been widely taught in our nation for at least the past 100 years. Please, learn to do it CORRECTLY before you become contagious.

          Comment


          • #6
            Quoth Jacen View Post
            It doesn't matter how hard the password is to guess, a lot of the time it'll be keyloggers taking the passwords
            Given. However, we're making sure that the fault isn't ours, which is the most important thing, and has been the source of many of my gripes about the company for years.

            Mystic: Log into the cPanel using the old password. It'll email you the temp password.
            Coworker: Distro of choice?
            Me: Gentoo.
            Coworker: Ahh. A Masochist. I thought so.

            Comment


            • #7
              You mean I actually have to log in?! BAH! </sc> j/k :P
              Getting offended is a great way to avoid answering questions that make you sound dumb. - exmocaptainmoroni

              Comment


              • #8
                While I understand you guys need to do what you have to...I would probably be one of those annoyed customers (but I would never call to complain about it!) I HATE it when I have to constantly change my password (work) and it has to be some complicated sequence so no one can guess it...including ME! I get why not having a simple password is needed but for me, since I have so many difference passwords...the more complex it needs to be, the worse it is! (My poor IT at work has to reset my password to get into my expense acct....i blame them though...they make me change it every 3 weeks and it can't be remotely the same as the previous 6...oy!!)
                Now, if you smell the roses but it doesn't lift your spirits, you're either allergic to rose pollen or you need medical intervention. ~ Seshat

                Comment


                • #9
                  Quoth Midorikawa View Post
                  Given. However, we're making sure that the fault isn't ours, which is the most important thing, and has been the source of many of my gripes about the company for years.
                  Yeah, say that to the 1500 WoW accounts being hacked everyday (only in EU, worldwide it's probably more like 6000-8000 / day).

                  And it's just so funny being berated for having "poor server security, which anyone can hack into" from someone that was hacked the third time this month and we told him thrice to check for keyloggers and change his password....
                  http://www.deezer.com/#music/album/100130
                  Melody Gardot

                  Comment


                  • #10
                    There's nothing that destroys security faster than making your users use passwords that are difficult to remember. That said, anyone that uses a "password" that doesn't include at least one number and is anything that can be found in a dictionary is going to be hacked.

                    One of the banking companies my boss uses makes her change it every 50 days or so, it has to be different from the last 8 passwords, and there are a few other rules, too. And, yes, the damn thing is written down (along with the last 6 or so) on a piece of paper within reach of the computer used to log into the bank, because it's too arcane for even someone like me, who already uses pass-phrases with numbers and characters to remember, much less your average user.

                    Another one changes every 30 days, so that one's got the month as part of the password so we don't actually have to write it down, but it's impossible to change it outside of their schedule without calling in to their tech support, which is a minimum 45 minutes on hold. >.<

                    But other than a single, polite-worded complaint to tech support, I don't kvetch.

                    ^-.-^
                    Faith is about what you do. It's about aspiring to be better and nobler and kinder than you are. It's about making sacrifices for the good of others. - Dresden

                    Comment


                    • #11
                      Regarding passwords written down within reach of the computer they're used on: I'm guilty of this, too. Granted, they're in a binder, which is in a cabinet, but it's not locked or anything. But considering I have 41 different passwords (I just counted them), and they all require different levels of complexity and expire at different times, can you blame me?
                      "I look at the stars. It's a clear night and the Milky Way seems so near. That's where I'll be going soon. "We are all star stuff." I suddenly remember Delenn's line from Joe's script. Not a bad prospect. I am not afraid. In the meantime, let me close my eyes and sense the beauty around me. And take that breath under the dark sky full of stars. Breathe in. Breathe out. That's all."
                      -Mira Furlan

                      Comment


                      • #12
                        I would love it if every business machine came with that fingerprint reader... just access all your programs with a thumbprint.

                        Last job I logged into the VPN with a random number generation fob, how hard would it have been to make that fob access just autolog all my work programs
                        EVE Online: 99% of the time you sit around waiting for something to happen, but that 1% of action is what hooks people like crack, you don't get interviewed by the BBC for a WoW raid.

                        Comment


                        • #13
                          I write down all my passwords.

                          In code, with a key I keep in my head.
                          The Rich keep getting richer because they keep doing what it was that made them rich. Ditto the Poor.
                          "Hy kan tell dey is schmot qvestions, dey is makink my head hurt."
                          Hoc spatio locantur.

                          Comment


                          • #14
                            Quoth AccountingDrone View Post
                            I would love it if every business machine came with that fingerprint reader... just access all your programs with a thumbprint.
                            Except that people like me pose a large challenge for fingerprint readers. I have very faint whorls, so the cracks on my hand from my skin being in bad condition are what actually gets red. These change frequently. I have to re-register my fingerprint every week or so, and even then it sometimes changes enough that I can't get into the fingerprint reader. They're also fairly easy to crack, so they're not good for secure applications.

                            Comment


                            • #15
                              Oh, I forgot about the fingerprint scanner. I don't use it very often, so I forgot about it.

                              Some of our employees have a lot of trouble getting their fingers to scan. The one who has the most trouble happens to be the one who uses it the most. She's also the sort of person who works a lot with her hands - shoveling, gardening, splitting wood, etc.

                              I hadn't heard that they're easy to crack. The company that requires us to use them for logging in to their site must not think so.
                              "I look at the stars. It's a clear night and the Milky Way seems so near. That's where I'll be going soon. "We are all star stuff." I suddenly remember Delenn's line from Joe's script. Not a bad prospect. I am not afraid. In the meantime, let me close my eyes and sense the beauty around me. And take that breath under the dark sky full of stars. Breathe in. Breathe out. That's all."
                              -Mira Furlan

                              Comment

                              Working...