Layer 8

Security is fundamentally about people, and everything we know about people is relevant to security. -- B. Schneier

Abusing the system.

I just decided that on one particular site that I use maybe twice a year, it’s easier to use the “forgot password” function and have the password reset every time I want to log in, rather than come up with a memorable password.  Why?  Because the challenge question, unlike the password, never has to be changed!

So I just put any old thing into the new password field, and forget about it until next time.

I’m sure this isn’t what the designers intended.

Posted by shrdlu on Monday, May 04, 2009
(1) CommentsPermalink blogmarks Favicon del.icio.us Favicon Digg Favicon Fark Favicon Furl Favicon Google Bookmarks Favicon StumbleUpon Favicon Technorati Favicon TailRank Favicon

Next entry: Let go, let Cloud.

Previous entry: Looking both ways.

Comments

.(JavaScript must be enabled to view this email address) Sweden on 05/04  at  11:55 AM:

Hi Shrdlu!  Yeah, I do the same thing with a couple of sites.  What cracks me up are those sites that have nothing sensitive or critical associated with them, yet they insist on complex 8-character passwords. 

Cheers,
Jack

Page 1 of 1 pages

Add a comment

Name:

Email:

Location:

URL:

Smileys

Remember my personal information

Notify me of follow-up comments?

Submit the word you see below: