|
|
|
|
|
by tsotha
4269 days ago
|
|
Having worked in places with those kinds of rules I can tell you most of those passwords is written down. At one government shop we did an audit and found the longer and and better a password is (and the faster it expires), the more likely users will write it down. Not only that, 70% of them put the written down password in their top right desk drawer. We also found a large percentage of our fancy two person authentication safes had both combinations written somewhere on the signout sheet. You can't make peoples' lives too difficult with security directives. They'll start to ignore you no matter how much you threaten them. |
|
One example of security. Someone (A) giving a breafing has someone (B) grabs at it so they can read the document. At which point (A) pulls his sidearm and threatens (B). Later (A) is given an intense debriefing to verify that he was willing to shoot (B) and simply wanted to clarify the situation vs being unwilling to shoot (B). (B) was later told he was lucky not to have been shot.