10 February 2009

Password Security

Recently, an email arrived in my NUS inbox concerning IT security. Specifically, NUS wishes to tighten password security by introducing a few requirements.


1) Passwords must be at least 8 characters in length.
2) Passwords must contain at least a number, an alphabet and a symbol (eg. Pa55Word!)
3) You will be required to change your password every 180 days.
4) You can change your password at most once/day.
5) You cannot re-use any of your 6 previous passwords.


Requirement 3, 4 and 5 are already in existence, which is pretty much one of the most stringent password requirements I've ever encountered. 1 and 2 are new, and while the former is reasonable, the latter is, well, a bit too much. Alphabet, okay; number, okay; but symbol too? Hey man, why not try this:



Can I suggest more? Ditch Internet Explorer for Firefox (some machines are still running IE6). Ditch Windows for Linux (at least for the mail server). But oh wait, NUS has a deal with Microsoft. Dang!

No comments: