Password

From Clinfowiki
Revision as of 04:14, 24 January 2007 by DeanSittg (Talk | contribs)

Jump to: navigation, search

We have had discussions at our organization about eliminating requirements to change passwords every x days, and to having different PW's for each application, in exchange for requiring one complex PW. Likely more secure? Any literature on breaches with this system vs the usual? Likely cost savings in PW resets by IS department?

Research firm RSA surveyed 1,700 enterprise end users in the US and found that more than a 1/4 of respondents manage more than 13 passwords at work [1]. This leads to much frustration on the part of both end users as well as IT managers who must help their users resolve password related problems which 40% of respondents said took at least 6 minutes each to resolve. This frustration causes over 50% of users to write down passwords on paper or save them locally on a spreadsheet or in document (often in plain text, i.e., no encryption) on their PC or handheld device.

References

Biometrics curing password headaches, 28 September 2005.