2007년 10월 25일 목요일

Blog #4

Title : On Beyond Open Sesame - Are we safe yet?
Author : Michael Schubach
Source : 2007 Hospitality Upgrade
http://www.hospitalityupgrade.com/_files/File_Articles/HUFall07_Password_AreWeSafeYet_Schubach.pdf

This article basically talks about keeping a password in secure. Some of people think that they are secure because they use a wonderful firewall and a great anti-everything software program with IT professional to protect them. These above things may make them feel secure but imagine that what if the guardian at the gate does not protect the system. It is going to be a disaster. So you need a secure password that actually provides enough protection.
So what is a secure password? They said “between six and eight characters long, contain letters of mixed case and non-letter characters, and cannot be found, in whole or part, in normal or reverse, in any dictionary of words or names in any language. The [user] is responsible for changing his or her password regularly.” And if one thing can be added more, it is “being careful not to repeat any of previous passwords.”
In ancient time, the purpose of the password is “the ability to recognize a stranger as friend or foe,” and the requirement of the password is “sufficiently challenging that foes cannot guess it but sufficiently easy that friends will remember it.” These days it can be a problem. IT professional says to create unique password to access the network but people do not have enough memory to remember passwords for all accounts that people registered. One interesting statistic said that the typical intensive computer user maintains 21 accounts that require a password. So our worst enemy may be us.
To be a good network custodian, we should keep in mind following.
1. Keep security requirements in perspective. We always consider that we have a sensitive data which should not be compromised.
2. Remember that there are alternatives to password security. As the technology developing, the ways of security is also increased. There are biometric options, security device that issues one-time entry codes, systems that remember faces and pictures instead of letters and phones and PDAs that provide encrypted password storage. These devices are good but there is one challenging: You remember the password and are not stolen them.
3. Don’t impose a standard so high that you end up with no standard at all. If your rule of network operation is too strict, your user will circumvent the rule and make their lives easy. It could make your enemy have a chance.
Maintaining system in secure is hard but we have to do. So we train our employees to make better password choice and suggest using acronyms as a password instead of words. There are several ways to keep system secure but I want to mention it instead of them; “It’s a jungle out there.”
When I was reading this article, I thought that how many accounts I have and the passwords of that accounts. I have several accounts which I regularly use and the passwords are similar each other. I tried to change the password before but changing the password is worse than not to change, because I could not remember it several days later. Therefore I spent more time to remember or find out the password by asking to system administrator.
Password security is always challengeable. Even if a new way is developed, there is one weak point that we remember at least one password to use it. That password should be creative and unique. Password security is continuously considerable.