About this site's lack of design: Yes, it's supposed to look this way — I'm helping create a new sandbox theme for WordPress (see it on GitHub).

Dan Rubin's SuperfluousBanter

Suffering from chronic idiocy since 1977

|

I Lost My Password

How usable is secu­rity? It’s a ques­tion I’ve been ask­ing myself
lately. One of the courses I attended last semes­ter was about cryp­tog­ra­phy and
secure design. What got me think­ing is the fact that secu­rity is just 20% technology—80%
is orga­ni­za­tional. Secu­rity is about people—about trust.

The thing is, the more you try to make a sys­tem secure the less usable it becomes—and
as a result, the sys­tem actu­ally becomes less secure than its design­ers intended.
Do you use dif­fer­ent pass­words for an assort­ment of accounts you are sub­scribed
to? Do you change your pass­words fre­quently? I cer­tainly don’t. Secu­rity
is always a trade-off between con­ve­nience and com­plex­ity. Peo­ple don’t
like com­plex­ity, and def­i­nitely not at 8:30 in the morn­ing when they need to
log in to start working.

If you ask users to mem­o­rize too many pass­words they will start stick­ing post-it
notes on their screen to make sure they don’t have to call tech sup­port.
How secure is that? You just spent 6 months and a few mil­lion bucks to end up
with bright yel­low post-it notes all over the place with con­fi­den­tial infor­ma­tion.
That’s why secu­rity is about peo­ple, not technology.

This item was posted by dhilhorst on Wednesday, March 31st, 2004.

Categories:

You can follow comments on this item via the RSS 2.0 feed.

Comments are closed.

4 comments on “I Lost My Password”

  1. Posted by Ben Scofield on Thursday, April 1st, 2004.

    The sit­u­a­tion gets even worse when you fac­tor in pass­word reminders and resets — if peo­ple don’t have access to or use encrypted email, then send­ing reminders that way is inse­cure. In that case, you’re basi­cally forced to pass­word resets (either by the user or — hor­rors — by the sys­tem). Argh!

  2. Posted by Sunny on Thursday, April 1st, 2004.

    Any sys­tem is as secure as the weak­est link. And the weak­est link is us — humans.

  3. Posted by Dustin on Thursday, April 1st, 2004.

    YES!

  4. Posted by Starlight on Friday, April 2nd, 2004.

    I read this hav­ing moments ago writ­ten a pass­word on a yel­low star shaped sticky note and putting it on my mon­i­tor until I can remem­ber it. I pon­dered this very thought at the moment when that action occurred.