Showing posts with label Password. Show all posts
Showing posts with label Password. Show all posts

Stored Password Encryption

Enabling Store Passwords Using Reversible Encryption determines whether Windows stores passwords using reversible encryption.

Enabling this is essentially the same as storing passwords in plain text which is insecure and not recommended. The purpose of this policy setting is to provide support for applications that use protocols that require knowledge of the user's password for authentication purposes. Enabling this policy setting should be a last resort used only in extreme situation where no alternative exists and application requirements outweigh the need to protect password information.

Store Passwords Using Reversible Encryption must be enabled when using CHAP (Challenge-Handshake Authentication Protocol)authentication through remote access or Internet Authentication Services (IAS). It is also required when using Digest Authentication in Internet Information Services (IIS).

Default: Disabled


View the original article here

Change Default Password

Wireless network routers and access points typically come with a built-in web interface that you can access to change the options and configuration settings. Like many other computer applications, accessing it is as simple as knowing the username and password.

The first step in securing your wireless network is the same as the first step for just about everything else in computers and computer networking -- always change the defaults. Any attacker can find out what the default username and password is for a given program or device in just a few minutes. The defaults may be great for letting you connect and get the device or program up and running quickly, but in order to keep snoopers or would-be attackers out, you must change the defaults as soon as possible.

Often, the default settings are so common that an attacker doesn't even need to do any research. Many vendors use Admin or Administrator as the username and something like "admin" or "password" as the password. A couple of "educated guesses" and an attacker could infiltrate your wireless router or access point.

Refer to the owner's manual for your particular device to learn how to access the administration and configuration screen, and change the default password as soon as you set the device set up. You can also check out our step-by-step instructions changing the default password on a network router. We also have guidance on how to choose a good, secure password.

Some vendors don't provide a means for changing the username, but if it is possible you should also change the default username. Knowing the username gives an attacker half of the information they need to gain access so leaving it set to the default is a security concern. If you can change it, make it something that won't be easily guessed. Don't use Admin or Administrator and avoid using simple usernames like your own first or last name.


View the original article here

Vista Password Policy

Open the Microsoft Windows Local Security Policy console and navigate to the Password Policies following these steps: Click on Start Click on Control Panel Click on Administrative Tools Click on Local Security Policy Click on the plus-sign in the left pane to open Account Policies Click on Password Policy

View the original article here

Password Security

One of the problems with passwords is that users forget them. In an effort to not forget them, they use simple things like their dog�s name, their son�s first name and birthdate, the name of the current month- anything that will give them a clue to remember what their password is.

For the curious hacker who has somehow gained access to your computer system this is the equivalent of locking your door and leaving the key under the doormat. Without even resorting to any specialized tools a hacker can discover your basic personal information- name, children�s names, birthdates, pets names, etc. and try all of those out as potential passwords.

To create a secure password that is easy for you to remember, follow these simple steps: Do not use personal information. You should never use personal information as a part of your password. It is very easy for someone to guess things like your last name, pet's name, child's birth date and other similar details. Do not use real words. There are tools available to help attackers guess your password. With today's computing power, it doesn't take long to try every word in the dictionary and find your password, so it is best if you do not use real words for your password. Mix different character types. You can make a password much more secure by mixing different types of characters. Use some uppercase letters along with lowercase letters, numbers and even special characters such as '&' or '%'. Use a passphrase. Rather than trying to remember a password created using various character types which is also not a word from the dictionary, you can use a passphrase. Think up a sentence or a line from a song or poem that you like and create a password using the first letter from each word.

For example, rather than just having a password like 'yr$1Hes', you could take a sentence such as "I like to read the About.com Internet / Network Security web site" and convert it to a password like 'il2rtA!nsws". By substituting the number '2' for the word 'to' and using an exclamation point in place of the 'i' for 'Internet', you can use a variety of character types and create a secure password that is hard to crack, but much easier for you to remember.

Use a password management tool. Another way to store and remember passwords securely is to use some sort of password management tool. These tools maintain a list of usernames and passwords in encrypted form. Some will even automatically fill in the username and password information on sites and applications.

Using the tips above will help you create passwords that are more secure, but you should still also follow the following tips: Use different passwords. You should usea different username and password for each login or application you are trying to protect. That way if one gets compromised the others are still safe. Another approach which is less secure, but provides a fair tradeoff between security and convenience, is to use one username and password for sites and applications that don't need the extra security, but use unique usernames and more secure passwords on sites such as your bank or credit card companies. Change your passwords. You should change your password at least every 30 to 60 days. You should also not re-use a password for at least a year. Enforce stronger passwords: Rather than relying on every user of the computer to understand and follow the instructions above, you can configure Microsot Windows password policies so that Windows will not accept passwords that don't meet the minimum requirements.

View the original article here

 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Information Computer and Technology - All Rights Reserved
Template Modify by Creating Website
Proudly powered by Blogger