Re: password expiry (was Re: [JOB / Recommendation] Evil documentation)

2002-07-16 Thread Aaron Trevena
On Tue, 16 Jul 2002, Michael Stevens wrote: > On Tue, Jul 16, 2002 at 01:34:19PM +0100, Nicholas Clark wrote: > > I'm not convinced that frequent password changing is good, because I find > > it seems to lead to either frequent password resetting by administrators > > (with inherent social engine

Re: password expiry (was Re: [JOB / Recommendation] Evil documentation)

2002-07-16 Thread Jonathan Peterson
Michael Stevens wrote: > On Tue, Jul 16, 2002 at 01:34:19PM +0100, Nicholas Clark wrote: > >>I'm not convinced that frequent password changing is good, because I find >>it seems to lead to either frequent password resetting by administrators >>(with inherent social engineering vulnerability) or

password expiry (was Re: [JOB / Recommendation] Evil documentation)

2002-07-16 Thread Nicholas Clark
On Tue, Jul 16, 2002 at 01:24:22PM +0100, Jonathan Peterson wrote: > My company needs some security policies and procedures documentation. > You know, the kind of thing that says in writing "Users must change > passwords every 30 days" and "Changes to firewall configuration must be Personally