Is Mandatory Frequent Password Changing at Universities Effective or Overkill?

  • Thread starter Thread starter Pengwuino
  • Start date Start date
Click For Summary
California State University, Fresno's IT department has implemented stringent password policies that require faculty to change passwords every three months, prohibiting the use of the last 12 passwords. This has led to frustration among faculty, who argue that such measures are unnecessary and cumbersome, especially since many have never experienced account compromises. Suggestions for coping with the rules include incrementally modifying existing passwords or using memorable phrases. The discussion highlights a broader critique of IT security practices, noting that overly complex password requirements can lead to insecure behaviors, such as writing passwords down or using predictable patterns. Participants shared experiences from various workplaces with similar policies, emphasizing the challenges of remembering multiple complex passwords and the ineffectiveness of such security measures. The conversation also touched on alternative security methods, like biometrics, and the paradox of increased security leading to decreased usability. Overall, the thread reflects a common sentiment that current password management practices may not effectively enhance security while complicating user experience.
  • #31
rhody said:
Pengwuino;

If you have friends in the IT Dept they can reset your pwd to what you prefer for you.
Don't ask how I know this... hehehe

This is nonsensical. People in IT Departments have no friends.
 
Physics news on Phys.org
  • #32
BobG said:
The passwords on the computer system I use are pretty sophisticated.

1. The password has to be at least 37 characters long and the number of characters has to be a prime number.
.
.
.
17. When logging on, you have 3 attempts to type your password in correctly. Typing in your password incorrectly 3 times will result in the entire system shutting down in a security lock down. You will need to read the installation computer security regulations in their entirety and pass a 100 question multiple question on-line test before being issued a new password. Logging in incorrectly 3 times and bringing the system to a halt twice in a 721 day period will result in termination of employment, along with expungement of all past and present passwords from your memory.

So basically, your entire company uses pencil and paper?
 
  • #33
Pengwuino said:
This is nonsensical. People in IT Departments have no friends.
I WAS the IT department of a very large multi-location ophthalmic practice. I had friends. Some people got ticked off at me when I enforced company policy on software, personal use, etc, but they all cozied right up when I was the only one available to get their PCs running right again and they were on deadlines.
 
  • #34
turbo-1 said:
I WAS the IT department of a very large multi-location ophthalmic practice. I had friends. Some people got ticked off at me when I enforced company policy on software, personal use, etc, but they all cozied right up when I was the only one available to get their PCs running right again and they were on deadlines.

1 person department? Doesn't count! :P
 
  • #35
Yep. We had offices in 6 towns and cities, interconnected with dedicated lines. Two of the offices had only one ophthalmologist on staff - the larger offices had maybe 8-10 docs, along with some optometrists, opticians, medical assistants and large clerical staffs. For IT, I was the only game in town(s).
 
  • #36
Our IT requires those sorts of frequent password changes too. I also do as Ivan suggests, and just keep changing a number in the password sequentially, except on the account that only uses a 6 character password...EXACTLY. That one is annoying...not 6 to 8, not at least 6, but exactly 6. I'm starting to run out of ideas for that one.

I like CSFITSUCKS! as a password though...I may need to adapt that one locally on the account that I always have to call for password resets on. :biggrin: As if the IT people don't hate me enough already. :smile:
 
  • #37
When I worked at Brooks College we had to change our passwords every few months too. Fortunately the IT department never wanted to have to deal with anything that they had not decided to do themselves so they made it easy on us and we could switch back and forth between two passwords.

MotoH said:
I like the idea of a small RFID device implanted in the hand, which will allow you to log onto the companies computers. Each one has its own profile, and the IT people can set it up as to what your access is.
It would have to be a device instead of just a tag. The code would likely need to be changed frequently unless they have figured out a way to keep third parties from scanning tags.
 

Similar threads

Replies
11
Views
678
  • · Replies 3 ·
Replies
3
Views
863
Replies
23
Views
2K
  • · Replies 15 ·
Replies
15
Views
2K
  • · Replies 12 ·
Replies
12
Views
6K
  • · Replies 119 ·
4
Replies
119
Views
15K
Replies
1
Views
2K
  • · Replies 7 ·
Replies
7
Views
4K
  • · Replies 27 ·
Replies
27
Views
4K
  • · Replies 2 ·
Replies
2
Views
2K