home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky sci.crypt:2720 comp.security.misc:779
- Newsgroups: sci.crypt,comp.security.misc
- Path: sparky!uunet!mcsun!dxcern!dscomsa.desy.de!zeus02.desy.de!hallam
- From: hallam@zeus02.desy.de (Phillip M. Hallam-Baker)
- Subject: Re: Keeping track of a lot of passwords
- Message-ID: <1992Jul23.015155.8364@dscomsf.desy.de>
- Sender: news@dscomsf.desy.de (USENET News System)
- Nntp-Posting-Host: zws015.desy.de
- Reply-To: hallam@zeus02.desy.de
- Organization: DESY ZEUS Central Data Acquisition
- References: <2a510a22@babyoil.ftp.com> <709960260@romeo.cs.duke.edu> <62453@cup.portal.com>
- Date: Thu, 23 Jul 1992 01:51:55 GMT
- Lines: 33
-
- In article <62453@cup.portal.com>, ts@cup.portal.com (Tim W Smith) writes:
-
- |>> I have accounts on half a dozen BBSes and unix boxes. I use different
- |>> passwords on each of them. BBSes are particularly insecure, since they
- |>> seem to invariably store passwords in plaintext. I think all are
- |>> pretty decent - not amazing, but hard to guess - passwords. They
- |>> required a bit of thought and memorization. I don't have them written
- |>> down anywhere. (For a while I had them in my home terminal emulator,
- |>> but decided to delete them, and yes I did make sure the bits were off
- |>> the disk.)
- |>
- |>Does anyone have a good way to deal with this? Not only might one have
- |>accounts on two or three machines for work, and accounts on various BBS
- |>and commercial services, but with the increasing availability of
- |>packages to encrypt files, one might have dozens of encrypted files on
- |>each machine.
-
- Easy you just write a line into your login.com to reconfigure the VT220
- so that the function keys have each of your hosts and passwords loaded
- into them. To log in all you need do is press a key, easy!
-
- Believe it or not we caught someone who did that. They didn't even clear
- the keys when they logged out "Oh you mean they stay loaded?"
-
-
- Nice thing about VMS, if somone does something really stupid security
- wise you can turn the password generator on to teach 'em a lesson. An
- expiry time of two weeks concentrates the mind wonderfuly.
-
- Because VMS is a real(TM) system you can set these things for individual users.
-
-
- Phill Hallam-Baker
-