Hacker News new | ask | show | jobs
by tsotha 4269 days ago
Having worked in places with those kinds of rules I can tell you most of those passwords is written down. At one government shop we did an audit and found the longer and and better a password is (and the faster it expires), the more likely users will write it down. Not only that, 70% of them put the written down password in their top right desk drawer.

We also found a large percentage of our fancy two person authentication safes had both combinations written somewhere on the signout sheet.

You can't make peoples' lives too difficult with security directives. They'll start to ignore you no matter how much you threaten them.

1 comments

No offence, but if your not going to fire people when you find their password written down then there going to write their password down. Written policies are practically irrelevant it's enforced policies people pay attention to.

One example of security. Someone (A) giving a breafing has someone (B) grabs at it so they can read the document. At which point (A) pulls his sidearm and threatens (B). Later (A) is given an intense debriefing to verify that he was willing to shoot (B) and simply wanted to clarify the situation vs being unwilling to shoot (B). (B) was later told he was lucky not to have been shot.

It doesn't matter if you fire people. You're not going to catch the vast majority of them, and they know it.
From what you said earlier you can catch 70% of them pretty easy.
Sure, if you go through all their stuff. And then what? Do we fire 70% of our staff?
Well, you could. Whether you should depends on the context, including importance of security, importance of institutional stability, other available mechanisms for punishment, &c...

But honestly, I mostly just thought the inconsistency between your two figures was amusing.

The inconsistency is a result of the fact that that number came from a one-time, expensive, intrusive audit that necessarily covered a subset of all our people. Even then we didn't go through anyone's wallet where I would expect to find at least that many.

After that the password policy was substantially relaxed so people could remember them more easily, and dire warnings were issued about writing them (and safe combinations) down. I moved on to a new job shortly after, so I'm not sure how much those warnings were taken to heart.