Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
The Employee Password Habits That Could Hurt Enterprises
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
12/20/2015 | 4:52:52 PM
Recipe for disaster
The password-changing policy is possibly the worst.  It makes no account for employees who actually have strong passwords and also fails to take into account actual risk.  That's how you get simple-to-guess/hack passwords.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
12/20/2015 | 4:51:34 PM
Re: Nice compliation of bad habits and statistics
Not to mention family members and friends who may become aware of their loved ones' passwords in other ways.

I once went on a date with someone who told me that because of her company's onerous password-changing requirements, she always just did a minor variation of the same (easy-to-guess) word.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
12/20/2015 | 4:49:50 PM
Re: We're all guilty
This is exactly why many security experts today advise what was once taboo advice -- that people write down their passwords, specifically to allow for greater complexity and entropy.  Better you write down your password and keep it in a secure place (for instance, not on a sticky note on your computer monitor) and it be super hard to remember than have an easy to remember (and easy to guess/hack) password that you don't write down.
RyonKnight
100%
0%
RyonKnight,
User Rank: Strategist
12/16/2015 | 3:29:56 AM
All on one page please
Article on one page please.  I'd like to read it but I'm not clicking through 10 pages.
BarbaraJohnson
50%
50%
BarbaraJohnson,
User Rank: Author
12/12/2015 | 7:22:21 PM
Nice compliation of bad habits and statistics
I especially like "*54% of employees share login information with family members so they can access their computers, smartphones and tablets" It's a good specific point to add into user awareness material.
Whoopty
50%
50%
Whoopty,
User Rank: Ninja
12/10/2015 | 7:34:49 AM
We're all guilty
I bet we're all guilty of something on this list, even those who are pretty good with password security. They're endlessly annoying though. You have to remember them, yet make them complicated and change them regularly. It's such a headache. 

The amount of services we all use now too, there's no way to remember everything. But then do you change your password storage login often? If you forget that, the pain-in-the-neck of having to reset everything is ridiculous.


97% of Americans Can't Ace a Basic Security Test
Steve Zurier, Contributing Writer,  5/20/2019
How a Manufacturing Firm Recovered from a Devastating Ransomware Attack
Kelly Jackson Higgins, Executive Editor at Dark Reading,  5/20/2019
TeamViewer Admits Breach from 2016
Dark Reading Staff 5/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Could you pass the hash, I really have to use the bathroom!
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-9892
PUBLISHED: 2019-05-22
An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged into OTRS as an agent user with appropriate permissions may try to import carefully crafted Report Statistics XML that will result in reading of arbit...
CVE-2019-10066
PUBLISHED: 2019-05-22
An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6, Community Edition 6.0.x through 6.0.17, and OTRSAppointmentCalendar 5.0.x through 5.0.12. An attacker who is logged into OTRS as an agent with appropriate permissions may create a carefully crafted calendar appointment i...
CVE-2019-10067
PUBLISHED: 2019-05-22
An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6 and Community Edition 5.0.x through 5.0.35 and 6.0.x through 6.0.17. An attacker who is logged into OTRS as an agent user with appropriate permissions may manipulate the URL to cause execution of JavaScript in the context...
CVE-2019-6513
PUBLISHED: 2019-05-21
An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.
CVE-2019-12270
PUBLISHED: 2019-05-21
OpenText Brava! Enterprise and Brava! Server 7.5 through 16.4 configure excessive permissions by default on Windows. During installation, a displaylistcache file share is created on the Windows server with full read and write permissions for the Everyone group at both the NTFS and Share levels. The ...