Click here to monitor SSC
SQLServerCentral is supported by Red Gate Software Ltd.
 
Log in  ::  Register  ::  Not logged in
 
 
 

Serious Security

By Steve Jones,

There's an interesting piece at Wired on hackers and their impact on security. Despite the constant hacks and cracks of passwords, the regular lectures and pieces written on the subject, many people refuse to use separate passwords on every site, or choose long passphrases, or implement many of the best practices that are published on security. Some of that might be a lack of knowledge, but much of it is likely explained by behavioral economics.

Most people are never hacked and don't have issues. Even if they do experience some problem, they can often recover fairly easily. Lots of hacks are just annoying, like using your email account to send SPAM, akin to random vandalism. As a result, many people don't bother to change their habits. It might also be a tendency that's hard-wired in our personalities. I've educated friends on passwords and given them Password Safe. A few use it religiously, but others keep forgetting, preferring to keep regenerating and changing passwords or re-using them.

To solve some of these issues and create the behavior that we want, there are suggestions in the article for software designers. One is requiring stronger mechanisms up front, another suggests perhaps changing from alphanumeric pass-phrases to image based ones. One poses the idea of enforcing penalties on users. These might be ways in which we can convince software users to take security more seriously. If it's true that software is eating the world, then perhaps the designers and developers should do their part to help make sure security is a part of the new world.

Steve Jones


The Voice of the DBA Podcasts

We publish three versions of the podcast each day for you to enjoy.

Everyday Jones

The podcast feeds are available at sqlservercentral.mevio.com. Comments are definitely appreciated and wanted, and you can get feeds from there. Overall RSS Feed: or now on iTunes!

Today's podcast features music by Everyday Jones. No relation, but I stumbled on to them and really like the music. Support this great duo at www.everydayjones.com.

You can also follow Steve Jones on Twitter:

Total article views: 110 | Views in the last 30 days: 1
 
Related Articles
FORUM

Passwords

Storing passwords securely

FORUM

Password change

Password change

FORUM

change password

change password

ARTICLE

Changing SQL Server Passwords

SQL Server 2000 does not have the best or most secure password mechanism. In fact it does a pretty p...

BLOG

Podcast Upgrades

A minor change for the podcasts next week. I got my wireless microphone, and I'm working with it a b...

Tags
editorial    
security    
 
Contribute

Join the most active online SQL Server Community

SQL knowledge, delivered daily, free:

Email address:  

You make SSC a better place

As a member of SQLServerCentral, you get free access to loads of fresh content: thousands of articles and SQL scripts, a library of free eBooks, a weekly database news roundup, a great Q & A platform… And it’s our huge, buzzing community of SQL Server Professionals that makes it such a success.

Join us!

Steve Jones
Editor, SQLServerCentral.com

Already a member? Jump in:

Email address:   Password:   Remember me: Forgotten your password?
Steve Jones