<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The future of passwords?</title><link>http://blogs.technet.com/robert_hensing/archive/2004/08/23/218903.aspx</link><description>Given what I do, I tend to be pretty interested in technologies that will allow me to do away with passwords altogether. One area that's shown promise in the past is the use of graphical passwords (again, demonstrating that passwords are an antiquated</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: The future of passwords?</title><link>http://blogs.technet.com/robert_hensing/archive/2004/08/23/218903.aspx#226923</link><pubDate>Wed, 08 Sep 2004 20:23:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:226923</guid><dc:creator>H. Carvey</dc:creator><description>It just goes to show...passwords aren't the issue...it's how passwords are used that's the issue.&lt;br&gt;&lt;br&gt;I remember doing password cracking as part of vulnerability assessments 5 years ago, using L0phtcrack.  In one case, we had a client w/ 3000+ users, and 85% of the SAM was cracked in 15 minutes.  This was partially due to the fact that no requirements were put in place for strong passwords, but also due to the fact that when the helpdesk reset someone's password to &amp;quot;password&amp;quot;, they didn't (or couldn't) force the user to change it when they first logged in...&lt;br&gt;&lt;br&gt;This is just a subset of the bigger issue w/ regards to infosec, and things like the Principle of Least Privilege and defense-in-depth...you can't say somethings not working if it hasn't been employed correctly to begin with.  Well...I take that back...you *can* say that, but it wouldn't be intellectually honest to do so...</description></item></channel></rss>