No not from me, but from the UK government.
GZ (thanks) sent a link through to this document" target="_blank">https://www.gov.uk/government/
The document is a little bit different to many other such advise handed out by many organisationsin that it is aimed more at system administrators rather than end users. As far as the actual advise to system administrators. It is nothing too revolutionary, but then we are dealing with passwords. And there isnt anything there that most of us wouldnt agree with. It does server as a little reminder that we should all be taking some care with passwords.
The 7 tips are:">">PrioritiseAdministrators and Remote user accounts
None are earth shattering, yet all of us know that pretty much every organisationhas users with passwords of Password123, Changeme, Welcome1 and of course Ashley Martin user favourites 123456. Numbers 1 and 7 feature in most penetration testing reports you read or write.
So whilst these tips provided by the UK government arent new or fantastic I would encourage you to spend a few minutes reading the document and on Monday see how your organisation meets, exceeds or perhaps fails in one or more of them.
Well be stuck with passwords for a while yet, we should at least make people work for them a bit harder.
Cheers
Mark H
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.