<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>aC forum: Password audit?</title>
  <link>http://www.activecollab.com/forums/topic/3051/</link>
  <description>Recent posts on topic: Password audit?</description>
  <dc:language>en-us</dc:language>
  <pubDate>Wed, 23 May 2012 01:59:55 CDT</pubDate>
  
  <item>
    <link>http://www.activecollab.com/forums/post/14181/#post14181</link>
    <guid>http://www.activecollab.com/forums/post/14181/#post14181</guid>
    <title>Post #3 by kthomas</title>
    <dc:creator>kthomas</dc:creator>
    <description><![CDATA[<p>Yeah,  I recently had to &quot;re-register&quot; for the UCB alumni site,  and not only did it give me a new (entirely random characters) username,  it forced a 10-character minimum password with requirements for letters, numbers,  caps and non-caps, etc.  What a burden for a site I log into once every two months!<br />
<br />
In this case,  mostly what I was looking for,  after having one &quot;break in,&quot; was a simple audit for passwords that were too obvious (clients' first initial plus last name),  or duplicate passwords across the same company (the final I can check manually, of course).<br />
<br />
I'm all for education,  but given a client base with multiple employees with various levels of experience,  it's clear to me that few are going to use something like the MS tool.  <br />
<br />
Now OpenID... openID... OpenID... !</p>]]></description>
    <pubDate>Wed, 30 Jul 2008 18:47:44 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/14159/#post14159</link>
    <guid>http://www.activecollab.com/forums/post/14159/#post14159</guid>
    <title>Post #2 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p>To check whether user passwords are strong enough? No, there is not. Existing passwords cannot be extracted because they are digested with sha1. <br />
<br />
What you can do is to tell your user what makes a good password and than point them to one of many password checker websites (<a href="http://www.microsoft.com/protect/yourself/password/checker.mspx" target="_blank" rel="nofollow">here's one</a> by Microsoft) to test strength of their password.<br />
<br />
Just a couple of days ago I had a discussion with a friend and she told me that it was hard for her to figure out a password that was strong enough to pass some stupid registration form. Some techie thought it was super important to hassle her about here password before she even used the system. I told her how I make passwords - I pick an object I bought, name it, than add it's price and finally one of its obvious properties. For instance:<br />
<br />
iMac189Kwhite24<br />
<br />
Now copy that password and check it with Microsoft password checker. Maybe that can help....</p>]]></description>
    <pubDate>Wed, 30 Jul 2008 00:28:10 CDT</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/14153/#post14153</link>
    <guid>http://www.activecollab.com/forums/post/14153/#post14153</guid>
    <title>Post #1 by kthomas</title>
    <dc:creator>kthomas</dc:creator>
    <description><![CDATA[<p>Is there a simple way to conduct password security audits?</p>]]></description>
    <pubDate>Tue, 29 Jul 2008 21:30:31 CDT</pubDate>
  </item>
</channel>
</rss>
