Tuesday, June 24, 2008

Reflections on Session 5

I was surprised that the class did not address thumbdrive security, patch management, dumpster diving, and social engineering more in their submissions.

In past years, the issues surrounded viruses, spyware, worms, and other malware. During the more recent semesters, the postings were on wireless issues (lack of encryption), server security, patch management, laptop (data-at-rest) and thumbdrive security, social engineering, shoulder surfing, tailgating, identity theft, and dumpster diving. This reflects a broader perspective of security beyond the intrusions from the World Wide Web.

Some students think that because of the exercise on alternatives to passwords, I am implying that passwords should be replaced totally. No, I am in favor of a two-factor authentication which typically includes a password or a PIN particularly when dealing with portal entry. I am disappointed with passwords themselves which are long, complex and impossible to memorize. And they say not to write it down. There MUST be a better system. I'm glad a few of you mentioned graphical passwords but that is still vulnerable to shoulder surfing!

Oh, yes, MISS RAMBO says...

1 comment:

Unknown said...

Often my situation Miss Rambo; I know exactly what you are talking about.