It's better than using the same one for all...
Companies should not ban employees from writing down their passwords because it forces users to use the same weak term on many systems, according to a Microsoft security guru.
Speaking on the opening day of the AusCERT conference on Australia's Gold Coast, Jesper Johansson, senior program manager for security policy at Microsoft, said the security industry had been giving out the wrong advice to users by telling them not to write down their passwords.
"How many have password policy that says under penalty of death you shall not write down your password?" asked Johansson, to which the majority of delegates raised their hands in agreement. "I claim that is absolutely wrong. I claim that password policy should say you should write down your password. I have 68 different passwords. If I am not allowed to write any of them down, guess what I am going to do? I am going to use the same password on every one of them," he said.
|