- Mar 3, 2001
- 8,859
- 4
- 0
I work at a law firm and currently we don't have any requirements for passwords. Also, people get up from their PC and leave for hours at a time without locking their desktop. I voiced my opinion about how much of a security risk that is and gave them examples of what people could do if they felt like being malicious.
Now, after a mangement meeting, they want me to turn on complexity rules. This is fine, but the people in this office are barely computer literate, and I don't think they will be able to remember a 8 character string with upper, lower, numbers, and symbols in it.
We're thinking about getting RSA ID devices for a few of the people who can't be bothered to remember such a password, but if they are using a PDA to sync their emails, they will have to type it in every time.
How do you guys do it?
Now, after a mangement meeting, they want me to turn on complexity rules. This is fine, but the people in this office are barely computer literate, and I don't think they will be able to remember a 8 character string with upper, lower, numbers, and symbols in it.
We're thinking about getting RSA ID devices for a few of the people who can't be bothered to remember such a password, but if they are using a PDA to sync their emails, they will have to type it in every time.
How do you guys do it?