<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
   <title>Information Systems Security</title>
   <link rel="alternate" type="text/html" href="http://blogs.nyu.edu/blogs/dm129/syssec/" />
   <link rel="self" type="application/atom+xml" href="http://blogs.nyu.edu/blogs/dm129/syssec/atom.xml" />
   <id>tag:blogs.nyu.edu,2010:/blogs/dm129/syssec/1685</id>
   <updated>2010-10-07T16:51:35Z</updated>
   <subtitle>Daniel Medina&apos;s blog for the NYU classes
Core Concepts of Information Systems Security, X52.9380
Advanced Information Systems Security, X52.9381</subtitle>
   <generator uri="http://www.sixapart.com/movabletype/">Movable Type Enterprise 1.52</generator>

<entry>
   <title>Open Thread (Week 1)</title>
   <link rel="alternate" type="text/html" href="http://blogs.nyu.edu/blogs/dm129/syssec/2010/10/open_thread_week_1.html" />
   <id>tag:blogs.nyu.edu,2010:/blogs/dm129/syssec//1685.69879</id>
   
   <published>2010-10-07T16:51:21Z</published>
   <updated>2010-10-07T16:51:35Z</updated>
   
   <summary>This is an open thread for the first week of Core Concepts of Information Systems Security (X52.9380). Welcome to the class!...</summary>
   <author>
      <name>Daniel Medina</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blogs.nyu.edu/blogs/dm129/syssec/">
      <![CDATA[<p>This is an open thread for the first week of <a href="http://www.scps.nyu.edu/course-detail/X52.9380/">Core Concepts of Information Systems Security</a> (X52.9380).  Welcome to the class!</p>]]>
      
   </content>
</entry>
<entry>
   <title>Mordac&apos;s authentication policies</title>
   <link rel="alternate" type="text/html" href="http://blogs.nyu.edu/blogs/dm129/syssec/2010/02/mordacs_authentication_policie.html" />
   <id>tag:blogs.nyu.edu,2010:/blogs/dm129/syssec//1685.58167</id>
   
   <published>2010-02-10T23:00:00Z</published>
   <updated>2010-10-07T16:35:43Z</updated>
   
   <summary>Orginally posted on 2009-03-04, and still true... Mordac first appeared as &quot;The Preventer&quot;, &quot;your liason from the Information Technology Department&quot;. This is his first appearance in the role of a security officer, implementing a policy we&apos;re probably now all very...</summary>
   <author>
      <name>Daniel Medina</name>
      
   </author>
   
   
   <content type="html" xml:lang="en" xml:base="http://blogs.nyu.edu/blogs/dm129/syssec/">
      <![CDATA[<p>Orginally posted on 2009-03-04, and still true...</p>

<p>Mordac first appeared as "The Preventer", "your liason from the Information Technology Department".</p>

<p>This is his first appearance in the role of a security officer, implementing a policy we're probably now all very familiar with:</p>

<p><a href="http://dilbert.com/strips/comic/1998-04-06/" title="Dilbert.com"><img src="http://dilbert.com/dyn/str_strip/000000000/00000000/0000000/000000/10000/2000/700/12717/12717.strip.gif" border="0" alt="Dilbert.com" width="100%"/></a></p>

<p>Let's compare that to <a href="http://www.nyu.edu/its/security/passwords/#create">NYU's password policies</a> ([although it has changed a bit] with enforced complexity, they make Mordac of 1998 look like a softie!):</p>

<blockquote>
   1. passwords must be 8 or more characters in length

<p>   2. must consist of letters (a-z and/or A-Z) AND at least one number (0-9) AND at least one special character: !@#$%^&*()_-+=[]|\;"~',&lt;&gt;./?</p>

<p>   3. the alphabetic portion of a password, taken as a whole, may not be a dictionary word proper name, or person's initials</p>

<p>   4. you may not reuse a password that you've previously used with NYUHome</p>

</blockquote>

<p>A decade later, the authentication policies became more complicated:</p>

<p><a href="http://dilbert.com/strips/comic/2007-11-16/" title="Dilbert.com"><img src="http://dilbert.com/dyn/str_strip/000000000/00000000/0000000/000000/00000/1000/700/1781/1781.strip.gif" border="0" alt="Dilbert.com" width="100%"/></a></p>

<p><a href="http://dilbert.com/strips/comic/2007-11-17/" title="Dilbert.com"><img src="http://dilbert.com/dyn/str_strip/000000000/00000000/0000000/000000/00000/1000/700/1782/1782.strip.gif" border="0" alt="Dilbert.com" width="100%"/></a></p>]]>
      
   </content>
</entry>

</feed>

