The Lowly Password

Ralph Spencer Poore · Information Systems Security · 1998

The password has long served as the traditional authenticator for system access. As the least expensive authentication method — one usually provided by vendors as a standard “feature” of their system — the much used password remains little understood in terms of its effectiveness. Here I describe a methodical approach to understanding passwords and their effectiveness. At some point in the future, perhaps biometric authentication will become the norm and we will no longer rely on passwords. Until that time, security administrators and computer auditors need to understand and properly implement password-based security schemes.

Read the paper · More papers on PaperTik