-
IT in Europe, Security Edition: Password security standards and trends
Passwords have long been a security problem. This IT in Europe: Security Edition looks at password trends and alternative forms of authentication. Learning Guide
-
Opinion: Firms can’t or won’t address social networking security risks
It's a common refrain: Even companies that are aware of social networking security risks don't do anything about them. Opinion
-
Alternatives to passwords: Replacing the ubiquitous authenticator
As the relative security of passwords falters, are they destined for obscurity? Feature
-
RSA Conference 2006
Can't make it to RSA 2006? Check out our continuous coverage from the show floor. Conference Coverage
-
Concerned about tablet security issues? Some are, others not so much
Users love their tablets, but security pros are concerned about tablet security issues. However, though tablets bring new threats, not everyone is ringing the alarm. News | 05 Dec 2011
-
Ignored password security policy leads to school data breach
Password reuse made it easy for a student hacker to get into the Gosport's Bay House School database and expose the details of nearly 20,000 people. News | 09 Aug 2011
-
Jericho Forum commandments address the future of identity management
The Jericho Forum recently released new guidance on what it believes could be an effective way to centrally manage users' ever-multiplying identities. News | 20 May 2011
-
Multiple Linux vulnerabilities found in Cisco videoconferencing systems
Multiple vulnerabilities in Cisco's video conferencing systems remain exploitable, enabling attackers to gain full control of the device to steal user passwords with little effort. Article | 18 Nov 2010
-
Researchers find 1.5 million stolen social networking passwords
A recently discovered stash of 1.5 million stolen passwords and credentials for social networking sites may usher in a new wave of U.K. cybercrime. Article | 26 Apr 2010
-
Microsoft, security firms warn of password meltdown
An increase in online shopping this season would be a boon to cybercriminals, who are conducting phishing and drive-by attacks in an attempt to profit from the holiday spirit. Article | 01 Dec 2009
-
Single sign-on software removes chaos and aids password management at East Kent NHS Trust
Until a recent single sign-on implementation, 8,000 members of staff at East Kent Hospitals University Foundation NHS Trust were drowning in a sea of different passwords that they needed to access various parts of the network. Article | 25 Nov 2009
-
Brute force attacks target Yahoo email accounts
Attackers target a background Web services authentication application used by ISPs and Web applications to authenticate users. Article | 17 Sep 2009
-
Unpatched vulnerability discovered in Microsoft SQL Server
Database security vendor Sentrigo today released some detail about a flaw discovered a year ago in Microsoft SQL Server that exposes passwords stored in memory as cleartext. Microsoft is not planning to patch this flaw. Sentrigo released a free utili... Article | 02 Sep 2009
-
Supplier's problems with passwords solved by single sign-on technology
A single sign-on product came to the rescue and saved a rail supplier's company from "password hell." Article | 27 Aug 2009
- See More: News on User Password Security
-
A pen tester’s perspective on creating a secure password
A pen tester explains the importance of creating a secure password Tip
-
How to prevent unauthorised personnel from hacking voicemail
Keeping attackers out of sensitive corporate voicemails can be as easy as updating PIN policies. Tip
-
The case for ongoing end-user security awareness training
Expert Michael Cobb makes the case for year-round end-user security awareness training. Tip
-
Network password security: Following password policy best practices
Regularly updating network password policies to keep pace with threats is essential to enterprise security. Learn about password policy best practices in this tip. Tip
-
The consequences of poor Microsoft SharePoint security permissions policies
The right Microsoft SharePoint security policy begins with proper permissions and access controls to internal resources. Tip
-
Windows password security policy and tools
All other security measures are irrelevant if strong passwords are ignored. Davey Winder discusses guidelines on how to create secure passwords and how Windows policy and tools can help ensure good passwords. Tip
-
Understanding multifactor authentication features in IAM suites
Enterprises often make the mistake of assuming that IAM suites come with tightly integrated multifactor authentication features, but in reality making sure they work together well can be a challenge. In this tip, IAM luminary Joel Dubin explains why ... Tip
-
Worst practices: Exposing IAM blunders
Simple IAM mistakes such as writing down passwords and unaudited user accounts can allow malicious access into corporate networks. In this tip, contributor Joel Dubin exposes the most common identity management and access control blunders, and enligh... Tip
-
Complex password compliance requirements made simple
In order to comply with a number of well-known industry regulations, it's necessary for enterprises to have stringent password management requirements in place. In this tip, expert Joel Dubin reviews the password requirements put forth by key complia... Tip
-
Adding 'fudge' to your passwords
Many end users easily have half a dozen passwords to access the various Web apps they need to do their jobs. With this tip, you can enforce strong password policies -- and allow your users to write down their passwords. Tip
- See More: Tips on User Password Security
-
How effective are password hack tools?
Richard Brain, our resident application and platform security expert, explains why strengthening a password is so important. Ask the Expert
-
How to protect employees' personal information and passwords
Even though employees are told over and over again to not give out their user names and passwords, it doesn't always work. Expert Ken Munro explains how to get through to your employees. Ask the Expert
-
How to prevent hackers from accessing your router security password
In this Q&A, Joel Dubin unveils the best practices for protecting a router security password from compromise. Ask the Expert
-
What is the best way to securely change the local administrator password in a domain?
Identity management and access control expert Joel Dubin unveils how a corporation can change local administrator accounts and passwords on a domain system. Ask the Expert
-
What type of protections should security question and answer authentication credentials have?
Identity management and access control expert Joel Dubin discusses how corporations can secure security question and answer authentication credentials. Ask the Expert
-
Will enabling Group Policy password settings affect existing user accounts?
In this expert response, identity management and access control expert Joel Dubin discusses the affect that Active Directory Group Policy password settings can have on user accounts. Ask the Expert
-
Are knowledge-based authentication systems doing more harm than good?
In this SearchSecurity.com Q&A, security expert Joel Dubin examines if the password security policies used in knowledge-based authentication systems are doing more harm than good. Ask the Expert
-
How should termination procedures address a user's multiple roles?
In this SearchSecurity.com Q&A, expert Joel Dubin explains how the right access management tools can eliminate all traces of a terminated employee. Ask the Expert
-
How to safely issue passwords to new users
In this Ask the Expert Q&A, our identity management and access control expert Joel Dubin offers tips on safe password distribution, and reviews the common mistakes that help desks and system administrators make when issuing new passwords. Ask the Expert
-
Will implementing two-factor authentication satisfy FFIEC requirements?
Considering implementing two-factor authentication to comply with the FFIEC guidance; read this Identity Management and Access Control Q&A. Our resident expert explains why financial institutions must use two-factor authentication methods by 2007 and... Ask the Expert
- See More: Expert Advice on User Password Security
-
Social networks and spear phishing attacks
Are your employees giving up valuable corporate information on social networking sites? Graham Cluley, senior consultant at Sophos Inc., explains how hackers can use data commonly found on LinkedIn to carry out effective spear phishing attacks. Video
-
IT in Europe, Security Edition: Password security standards and trends
Passwords have long been a security problem. This IT in Europe: Security Edition looks at password trends and alternative forms of authentication. Learning Guide
-
Opinion: Firms can’t or won’t address social networking security risks
It's a common refrain: Even companies that are aware of social networking security risks don't do anything about them. Opinion
-
Alternatives to passwords: Replacing the ubiquitous authenticator
As the relative security of passwords falters, are they destined for obscurity? Feature
-
A pen tester’s perspective on creating a secure password
A pen tester explains the importance of creating a secure password Tip
-
How to prevent unauthorised personnel from hacking voicemail
Keeping attackers out of sensitive corporate voicemails can be as easy as updating PIN policies. Tip
-
Concerned about tablet security issues? Some are, others not so much
Users love their tablets, but security pros are concerned about tablet security issues. However, though tablets bring new threats, not everyone is ringing the alarm. News
-
The case for ongoing end-user security awareness training
Expert Michael Cobb makes the case for year-round end-user security awareness training. Tip
-
Ignored password security policy leads to school data breach
Password reuse made it easy for a student hacker to get into the Gosport's Bay House School database and expose the details of nearly 20,000 people. News
-
Jericho Forum commandments address the future of identity management
The Jericho Forum recently released new guidance on what it believes could be an effective way to centrally manage users' ever-multiplying identities. News
-
Multiple Linux vulnerabilities found in Cisco videoconferencing systems
Multiple vulnerabilities in Cisco's video conferencing systems remain exploitable, enabling attackers to gain full control of the device to steal user passwords with little effort. Article
- See More: All on User Password Security
About User Password Security
Get advice on how to bulk up your corporation's user password security with management software and systems that manage passwords and administer password policies.