iPedia.net
Home - Information - Dictionary - Articles - Video - Web

What Your Users Don't Know About Password Security Can Hurt You

Most especially if they don't know but are so mind-numbingly obstinate that they won't admit they are wrong, even when proven so.


I post this question to you: If I post the most commonly used passwords in the user database of a large website, can you do anything with that? You don't have the usernames or emails. You don't have any unique passwords, just the 5 most common ones, which hundreds or thousands of people use. Something like:

Ok, now you probably know the 5 most common passwords for AOL, MSN, Wikipedia, Fark, Digg, MetaFilter and most likely Slashdot. What are you going to do with those? By posting this here, have I lessened the security of any of those services?

The answer is a resounding NO.

Yet yesterday I posted just such passwords on a public forum, during a discussion on bad passwords and password security. Users, not being at all familiar with security FREAKED THE HELL OUT. I was called incompetent, foolish, amoral, unethical and more. One of the people even emailed my boss to complain about this 'breach of trust'. When it came down to proving to them that there was no security flaw created, then claimed it was unethical. When it was clear there was no ethics problem, they called it a violation of the account owners' Terms of Service. When it was clear that was not the case they claimed I broke standard 'business rules'.

I even had one foolish individual claim that their 'perceived threat' was a 'real threat'; that the bogeyman in the closet was real because the kid hiding under the covers was frightened of shadows.

I have to shake my head at the illogic here, but I learned something. When it comes to users, their lack of knowledge can be more important than the knowledge they have and share, as far as keeping the peace on the forum they are participating in. It was also drilled into my head, once again, that I should never underestimate the stupidity of groups, even when taken on an individual basis the members of that group can be quite intelligent.

And so, you learn from my example: assume a lack of logic, not an abundance of it.

I've been involved in managing online discussion forums of various sorts since about 1996. Having spent all that time, I've developed a reasonable sense of what does and does not work, where discussion forums fail and what (often nothing) can be done to bring them back from the brink of failure.

I wrote a blog before the term 'weblog' came into common usage, and from there developed small internet communities ranging from a community for beginners in the Perl programming language, to advocates for geek rights and against workplace bullying, and ultimately was instrumental in developing the community for the popular comic strip User Friendly. I have a certificate in conflict resolution and I'm not afraid to use it...or ignore it if the case may be. I'm a moderator and administrator and I can help you solve the internet discussion forum issues you are having difficulty with.


...click on link for more information and related articles.


AddThis Social Bookmark Button    Digg this article.

Other articles

    Article Categories
     

    Albums, songs and lyrics - Hotels & Maps - Music & Cinema Encyclopedia
    All content on this website, including articles, information, pictures, dictionary, and other reference data is for informational purposes only. This information should not be considered complete, up to date, and is not intended to be used in place of a visit, consultation, or advice of a legal, medical, or any other professional.
    page counter