Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From what you said earlier you can catch 70% of them pretty easy.


Sure, if you go through all their stuff. And then what? Do we fire 70% of our staff?


Well, you could. Whether you should depends on the context, including importance of security, importance of institutional stability, other available mechanisms for punishment, &c...

But honestly, I mostly just thought the inconsistency between your two figures was amusing.


The inconsistency is a result of the fact that that number came from a one-time, expensive, intrusive audit that necessarily covered a subset of all our people. Even then we didn't go through anyone's wallet where I would expect to find at least that many.

After that the password policy was substantially relaxed so people could remember them more easily, and dire warnings were issued about writing them (and safe combinations) down. I moved on to a new job shortly after, so I'm not sure how much those warnings were taken to heart.


Well, wallet is a much better place than desk drawer.

https://www.schneier.com/blog/archives/2005/06/write_down_yo...

Still may or may not be acceptable, depending on context.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: