SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Information Architecture >> Identity Management

Users suffering password overload

Users suffering password overload

By:  Jeff Jedras  On: 10 Nov 2005 For: ComputerWorld Canada Creator

The average corporate IT user is being asked to remember an increasing number of passwords and is resorting to insecure ways to remember them, thus opening the IT infrastructure to risk and placing a heavy burden on help desks, according to a recent survey.

The average corporate IT user is being asked to remember an increasing number of passwords and is resorting to insecure ways to remember them, thus opening the IT infrastructure to risk and placing a heavy burden on help desks, according to a recent survey.

Conducted for Bedford, Mass.-based authentication and encryption company RSA Security by research group Current Analysis, the survey of 1,700 enterprise technology end users in the U.S. showed 30 per cent of users are required to remember six to 12 passwords at work, and 23 per cent need to remember 15 or more. And to remember them, 25 per cent store a master list on their computer, 22 per cent on a PDA or handheld, and 15 per cent keep a paper list by their desk.

Victor DeMarines, RSA’s senior product manager, said the upward trend in the number of passwords wasn’t a surprise, but the sheer numbers that the burden has reached was. He added that the results confirmed that compliance audits have caused companies to increase their password policies and enforcement, requiring passwords to be changed more often and be more complex.

“When you contrast that with the number of passwords they’re managing, you can see it becomes a really complex environment for the end user,” said DeMarines.

User angst is simmering, with 88 per cent of respondents classifying their password situation from somewhat frustrating to very frustrating. And with 82 per cent of users saying restoring a forgotten password requires help desk intervention, it’s also frustrating for the IT department.

Rather than securing the IT infrastructure, DeMarines said harsher password enforcement is only encouraging risky behaviour, such as lists on PDAs, and companies need to find a balance.

He said companies should look at tweaking their policies, or consider technology answers like enterprise single sign-on (ESSO) that let users access multiple applications through one password.

As Philadelphia law firm Post and Schell began to reassess its physical and IT security procedures to comply with government regulations, chief technology officer Louis Mazzio said it quickly became clear that without help, the situation would become unmanageable for their users.

Mazzio said as they moved to electronic documents they wanted to have the same security they had with their locked file cabinet room. Using technology from RSA, Mazzio said each employee now has one smart card with their photo that acts as their company ID as well as their building, elevator and office key card. Each computer has an attached card reader, and combined with their password it gives the user access to areas of the network they’re authorized to use.

Joe Greene, vice-president of IT security research for IDC Canada in Ottawa, said identity and access management are key components to any sound security program. Many people still tend to use simple passwords they can remember, like their kids’ names or birthdays, and he said that can be a problem.


Sign up for our Newsletters












Print |  Views: 598   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Jeff Jedras Jeff Jedras joined CDN as a senior writer in 2007. While he was new to the channel he was no stranger to technology journalism, beginning his career in Ottawa with Silicon Valley NORTH in 1998, where he... more

Related Content

How dangerous user behaviour puts networks at risk
How dangerous user behaviour puts networks at riskRecent research from the Ponemon Institute revealed that a majority of users disobey company security standards -- and they do so knowingly. In addition, survey data just released by RSA shows that trusted insiders create data exposures of extraordinary scope through their everyday behaviours. Here are some behaviours to watch for and guard against.
Data security will be the focus next year
Data security will be the focus next yearRegulatory requirements and increasing consumer concerns about information security breaches are making data-level security controls a top priority for 2007, according to IT managers at the Computer Security Institute (CSI) trade show in Orlando this week.
Experiments in innovation – Interview with Symantec CTO, Ajei Gopal
Experiments in innovation – Interview with Symantec CTO, Ajei GopalSymantec Corp. funnels a portion of its R&D budget each year into technology innovation. The "crucible" where innovative technologies are forged is Symantec Research Labs (SRL). Ajei Gopal, Symantec's chief technology officer, talks to Joaquim P. Menezes, IT World Canada's Web editor about thes labs and how they focus on the proverbial "next thing."
Wireless LAN security vs. convenience - walking the tightrope
by joaquim p. menezes - “security vs. ease of use” – is a conundrum a lot of network managers face when it comes to wir
Dan Swanson's Security Resources: #3
there are several ongoing, long-term security efforts worth examining. the national institute of standards and technology (nist) has published hundreds of guidance documents relating to all aspects of information security over the years. just as importantly, they consistenly maintain the currency of their guidance. the center for internet security (cis) has developed dozens of consensus-based sec
McAfee coming to an Intel laptop, MID near you
security vendor mcafee announced yesterday its plans to extend its products to intel-based laptops and mobile internet devices (mids).integrated data encryption and integrated mobile content security will be provided for laptops and mids using intel atom processor z5xx series and moblin-based software.intel's anti-theft technology and active management techn

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.