create account

Are Users at Fault for Weak Passwords? by mrosenquist

View this thread on: hive.blogpeakd.comecency.com
· @mrosenquist ·
$0.96
Are Users at Fault for Weak Passwords?
![Admin.png](https://cdn.steemitimages.com/DQmSiYBYaNnrZmNNzUcoZiFoGXLFVJym4CVt9b16qFbfuST/Admin.png)

Story Source: https://www.bleepingcomputer.com/news/security/vodafone-tells-hacked-customers-with-1234-password-to-pay-back-money/

Scratching my head wondering why a system administrator who defines and enforces the security policy is blaming it's users for weak passwords? 

Service owners can set the minimum criteria for password strength, complexity, and expiration. They can also test users choices against lists of known common passwords. If there are unacceptable risks, additional services can be included to protect access, such as change notifications, login-tracking communications, and Multi-Factor Authentication (MFA) mechanisms. 

If you built and oversee the system, why would you vilify those who operate within the acceptable parameters you have defined?
👍  , , , , , , , , , , , , , , , , , , , ,
properties (23)
authormrosenquist
permlinkare-users-at-fault-for-weak-passwords
categorysecurity
json_metadata{"tags":["security","news","technology","password","hack"],"image":["https://cdn.steemitimages.com/DQmSiYBYaNnrZmNNzUcoZiFoGXLFVJym4CVt9b16qFbfuST/Admin.png"],"links":["https://www.bleepingcomputer.com/news/security/vodafone-tells-hacked-customers-with-1234-password-to-pay-back-money/"],"app":"steemit/0.1","format":"markdown"}
created2018-09-06 23:41:57
last_update2018-09-06 23:41:57
depth0
children5
last_payout2018-09-13 23:41:57
cashout_time1969-12-31 23:59:59
total_payout_value0.746 HBD
curator_payout_value0.211 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length876
author_reputation178,128,965,781,896
root_title"Are Users at Fault for Weak Passwords?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id70,551,283
net_rshares906,791,289,459
author_curate_reward""
vote details (21)
@goblu96 ·
$0.40
i agree with you, password strength is an administrator setting (and has been for a significant period of time).  If you allow weak passwords, there is no way you can blame the users.
👍  , ,
properties (23)
authorgoblu96
permlinkre-mrosenquist-are-users-at-fault-for-weak-passwords-20180907t130122847z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-07 13:01:24
last_update2018-09-07 13:01:24
depth1
children0
last_payout2018-09-14 13:01:24
cashout_time1969-12-31 23:59:59
total_payout_value0.298 HBD
curator_payout_value0.097 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length183
author_reputation895,122,805,291
root_title"Are Users at Fault for Weak Passwords?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id70,604,208
net_rshares374,877,208,085
author_curate_reward""
vote details (3)
@jacobite ·
$0.08
The users are not to be blamed in the Vodafone case.

Now queries and filters can be defined for passwords acceptance. 

Even now auto-generated password is the order of the day
👍  
properties (23)
authorjacobite
permlinkre-mrosenquist-are-users-at-fault-for-weak-passwords-20180906t235636024z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-06 23:56:39
last_update2018-09-06 23:56:39
depth1
children0
last_payout2018-09-13 23:56:39
cashout_time1969-12-31 23:59:59
total_payout_value0.058 HBD
curator_payout_value0.018 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length177
author_reputation7,207,277,127,041
root_title"Are Users at Fault for Weak Passwords?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id70,552,153
net_rshares73,023,418,023
author_curate_reward""
vote details (1)
@magic8ball ·
To the question in your title, my Magic 8-Ball says:<blockquote>Without a doubt</blockquote><hr>*Hi! I'm a bot, and this answer was posted automatically. Check [this post out](https://steemit.com/introduceyourself/@magic8ball/introducing-the-magic-8-ball-bot) for more information.*
properties (22)
authormagic8ball
permlink20180906t234204045z
categorysecurity
json_metadata{"tags":["test"],"app":"steemjs/examples"}
created2018-09-06 23:42:03
last_update2018-09-06 23:42:03
depth1
children0
last_payout2018-09-13 23:42:03
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length282
author_reputation-271,108,124,950
root_title"Are Users at Fault for Weak Passwords?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id70,551,289
net_rshares0
@mchavarriaot ·
$0.38
They're supposed to pay back $ after their accounts were hacked? How does that make any sense?
👍  
properties (23)
authormchavarriaot
permlinkre-mrosenquist-are-users-at-fault-for-weak-passwords-20180908t060300856z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-08 06:03:03
last_update2018-09-08 06:03:03
depth1
children0
last_payout2018-09-15 06:03:03
cashout_time1969-12-31 23:59:59
total_payout_value0.371 HBD
curator_payout_value0.004 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length94
author_reputation617,296,971,735
root_title"Are Users at Fault for Weak Passwords?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id70,672,260
net_rshares361,372,299,451
author_curate_reward""
vote details (1)
@ultimus ·
$0.40
Many years ago when there weren't admin tools to define password requirements and check against common hashes, but nowadays system owners literally define and have great control over what is acceptable.   I can't blame the user as they will follow what is most convenient and acceptable.
👍  , ,
properties (23)
authorultimus
permlinkre-mrosenquist-are-users-at-fault-for-weak-passwords-20180907t005129482z
categorysecurity
json_metadata{"tags":["security"],"app":"steemit/0.1"}
created2018-09-07 00:51:33
last_update2018-09-07 00:51:33
depth1
children0
last_payout2018-09-14 00:51:33
cashout_time1969-12-31 23:59:59
total_payout_value0.396 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length287
author_reputation6,664,676,750,516
root_title"Are Users at Fault for Weak Passwords?"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id70,555,641
net_rshares375,255,205,267
author_curate_reward""
vote details (3)