Forum Discussion
What security threats do you experience the most?
You make an interesting point about the complicated and/or long passwords being too difficult for end users to remember Moombas
What do you think would be a good solution to handle passwords? Is it a good idea to allow end users to write them down? Maybe they could do so in a more secure way...
No, writing down is definitely nothing they should do ever.
But IT needs to find a good solution in case of good password settings, which the end user may be able to remember because with the good (not too complicated) password (but still matching character rules) which also may then result in the less need of renewing it.
This could lead to less written down passwords.
But in general, i still raise my hand for Authenticators being used as MFA or even additional to the password a physical device like employee card or finger print being used.
And just to add here: Sometimes you also just need to be creative to find a good way to create your own good passwords.
Example: Year-Day-SystemToAccess-SomethingUnique
Result of Example: 2023-05-Java-IHate
This contains automatically numbers, characters and (Capital) letters where year and day is the one you changed the password for example.
So everything is something you can somehow easy remember and just need to put in together and being different from system to system.
- Emilie_B9 days agoGoogle Community Manager
Thank you for sharing Moombas!
Your method to generate passwords sounds very efficient (and I will definitely bookmark it for future use 😉).
- Moombas9 days agoLevel 4.1: Jelly Bean
It's just an example and shows even if you need complex passwords, you could make it a bit easier even if you in addition replace letters by numbers instead but keeping some kind of same syntax and so on but this is "user based password training" but still less secure than using an additional physical access.
And just a related link to it (sry for the German but in my opinion fits to 100% my opinion): https://www.notebookcheck.com/Chaos-Computer-Club-fordert-Abschaffung-des-AEndere-Dein-Passwort-Tags.955034.0.html