Stop reading for a moment and have a quick tour around your office, pay special attention to monitors and come back.
Is it covered in sticky notes? Try to gaze over the sticky notes. Trust me; you’ll be amazed of what you can get out of these tiny yellow notes! In addition to irrational childhood fears that still haunt your colleges you will find loads of numbers and meaningless phrases, if you think about it then you’ll know that PINs and Passwords are all over the place!
Users will find it much easier to write down an 8-character word on a sticky ‘Post-It’ note than actually memorizing it! The truth is, Post-It notes are not one of the most secure ways to protect passwords, I’m not telling you to stop buying it, it’s a great product. However, Post-It does very little in the way of information security. And user’s may feel surprised to know that putting another sticky note on top of the original in an effort to shield its contents isn’t enough either. So you should find a way for your users to stop doing it! But don’t go so hard on your users, most people write personal information on sticky papers because they are too difficult to remember, or they are just too many!
Forcing users to use complex passwords specially when you have so many applications within your environment will not give you the level of security you’re looking for, even if you try to lock the sticky notes in a safety deposit box, users will find strange places to write passwords; on margin of a book they keep in their desk, underside of their chairs, even tattoo it on a co-worker’s neck! If you are really concerned about your network security and you want to make user’s life easier consider using a Single sign-on solution.
Single Sign-On (SSO) solutions will help you to apply the most complex password policies while keeping user friendliness in place, user’s will only need to remember one single secure password, and all other application passwords can be generated automatically to the level of complexity you require, the good thing is users do not need to be involved in generating these passwords, the solution will generate, update and securely store these information without any user intervention. Not only that, with SSO it is easier to audit who is allowed to access which applications, who actively uses accounts in which system and who has accessed to which system and when.
Enterprise Single Sign-On solutions are pretty matured now, and it can even eliminate the need for users to remember a single password, SSO solutions can utilize Smartcards with certificates and other credentials stored on tokens, with this users will not be involved in any password-related activities, a true strong authentication with heterogeneous applications and platforms can be easily achieved, no wonder that SSO is becoming so trendy!
SSO is not only a trend, it is a complete solution to a very old problem, raising security level and keeping users away from writing it on a sticky note!! And don’t forget, after implementing such solution check out your Post-It spending, and calculate your savings!!!
Bilal Alhmoud,
Senior Consultant
QME Software