Wednesday, 8 August 2018

Your Password

There is so much idiocy about security. Banks tell us to hide our PIN, enter it under a cover so you can't see what you are typing, treat everyone as a potential thief and then make your cards contactless, no ID required (apart from odd random PIN requests).

I've always believed that much more than four passwords becomes a security risk, because people start writing them down. The only secure place for a password is in your head and it has to be something that you can remember, maybe a phrase with a smattering of numbers and other characters.

When I worked for Littlewoods on their IT systems the backspace was considered a valid character for a password, so if you made a mistake you had to completely start again with your log in.

There are systems that won't allow sequences, repetitions, numbers, special characters and these again generate security risks because people end up writing down passwords.

There are even software packages that remember your passwords for you. Think about that. You are entrusting all your logins to a piece of software, that is the digital equivalent of your notebook that you give to someone else for safekeeping. I was also amazed to see the number of password notebooks for sale on Amazon, it's like people want to give away their information, although if you think of your Tesco and Boots clubcards that track all your purchases, and Facebook where you publicly share so much personal information.

Facebook, Google and Paypal always ask me if I want to stay logged in, now how insecure is that. You enter a system securely and when you are finished you log out. The really annoying thing is that they use cookies to remember your preferences. Cookies are by their nature transient, and I always clear my web cache because I do web work and want a clean browser cache, which means all the particular site starts asking me for all sorts of things. To log into Facebook or this blog I am asked three times if I want to save my password.

Though again this blog is me sharing my thoughts with you.

I have had many arguments about IT security over the years, and it seems to me, often people do things because they can or it gives them control, rather than it's a good idea.

Fingerprints , Face Recognition and Retina scanning are more security options but my friend Nic managed to lock himself out of his iPhone when he accidentally sanded off his fingerprints.

So what else to play but "Security" by The Saints.

