Computing.Net > Forums > Security and Virus > Password Reset Questions (Policy)

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Password Reset Questions (Policy)

Reply to Message Icon

Name: william344
Date: August 4, 2005 at 07:58:09 Pacific
OS: Windows 2000
CPU/Ram: P III
Comment:

Good morning;

I am interested in getting a feel for what types of questions different organizations use for 'password reset questions' which allow a user to reset a password for themselves.
I feel reset questions should be something users would not easily be socially engineered out of (i.e. the last 4 digits of their social security number). I am looking for some precidence that I can take to the management of my organization and make it policy.

Thanks!
Bill



Sponsored Link
Ads by Google

Response Number 1
Name: OrionCA
Date: August 4, 2005 at 17:07:33 Pacific
Reply:

Good practice is not to allow any dictionary words or words followed by a string of numbers: PASSWORD1, PASSWORD001, etc, are right out. A1l2t3r4n5t6i7n8g letters and numbers works pretty well, although you don't want something as simple as this numerical sequence, nor anything with your Social Security Number, phone number, house number, etc., in it.

There are a number of online password crackers you can use to check users' passwords to make sure they aren't easy to crack.


0

Response Number 2
Name: XpUser
Date: August 4, 2005 at 17:17:19 Pacific
Reply:

Here is another good practice that may shock the management of your organization. In this article, M$ security guru said that companies should not ban employees from writing down their passwords because such bans force people to use the same weak term on many systems.

i_XpUser


0

Response Number 3
Name: abc123abc123
Date: September 21, 2005 at 21:37:04 Pacific
Reply:

It looks like the previous respondents didn't actually answer the question that had been asked.

Some examples of password self service reset questions are:

City (town, village) where you were born
Father's middle name
Favorite (or least favorite) food
Favorite (or dream) vacation location
Make/model of your first car
Name of the hospital where you were born
Name of your first pet


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Password Reset Questions (Policy)

BIOS password reset www.computing.net/answers/security/bios-password-reset/107.html

password resetting www.computing.net/answers/security/password-resetting/21163.html

password reset www.computing.net/answers/security/password-reset/27870.html