Network Security: A Practical Approach

Deciding who has access to what
Social aspects of password policy
Creating strong passwords
Securing password files
Password audits
Automating password management
Passwords are both the bane and the foundation of network security. Until recently, a matching user name and password pair were the only form of user identification available to most network installations. Nonetheless, despite the increasing affordability and accessibility of biometric identification devices, passwords still remain the most widely used way to provide secure access to computing facilities.
In this chapter, we ll discuss the issues surrounding passwords and password management, including password audits. The chapter-ending Hands On section covers password management software, both from a network and an individual point of view.
In Chapter 1, you saw an example of a password policy. Do you really need a written password policy with the kind of detail you saw there? In any organization that has more than a handful of employees, probably you do. Given that passwords are a network s first line of defense, it pays to be overly cautious.
General password wisdom says that users should create strong passwords more on strong passwords shortly and that passwords should be changed every 60 days or so. New passwords should not use any portion of the preceding password. For example, users shouldn t take a word and simply add a different number at the end each time they recreate their password, nor should they be able to reuse passwords...