Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Are passwords a waste of time?

Bob Bragdon takes on the notion that strong passwords and most other security controls make employees less productive

I apologize up front for jumping into this debate, but I couldn't resist. Not a week goes by, or so it seems, without some newspaper, magazine or TV show (apologies to my media brethren) lambasting security and IT professionals because they force unnecessary security controls on the poor, downtrodden consumer or worker. It's as if your security requirements are designed to make everyone's life miserable with little or no benefit. You evil CSOs! My heart bleeds for the poor peasants whom you oppress.

Last month, for example, the Boston Globe examined a Microsoft Research study that concluded, according to the article, that "many of these irritating security measures are a waste of time." I can certainly relate to that. I'm annoyed every time I need to enter my 15-character complex password, which I must do several times a day in the office and even more often when I'm traveling. I'm annoyed every 90 days when I have to come up with a new complex password that can't be the same as one I've used any time in the past 20 years. But I also recognize that simple passwords--pet's names, children's names, and so on--are easily broken. And I realize that there are other sides to this argument.

Also see Ira Winkler on security awareness training

When we discuss whether security measures are worthwhile or not, we need to consider the point of view from which we examine the issue. Often it's the user's point of view, so the focus is on all the time they spend entering long passwords or navigating security controls, which results in millions of hours of lost productivity. I buy that.

What I don't buy is that most workers would be significantly more productive if freed from these controls. End users, whether bank customers or your own employees, are by far the weakest link in the security chain. Let's not kid ourselves: Security controls are more about protecting the business than the individuals themselves.

I can already hear the outcry that would arise if a company opted to use simple passwords and ultimately had a data breach (safe bet). The lawyers, as they filed their class-action lawsuits, would be asking why complex passwords weren't required. The media (with all due deference) would paint a picture of an uncaring corporate behemoth. Shame on the CEO. Please, give me a break.

This argument isn't about the cost-benefit trade-off of time versus security. It isn't about the end user's productivity or inconvenience. It's about protecting the business's reputation and reducing risk.

I give Cormac Herley, the Microsoft researcher who conducted this study, a lot of credit for really looking at the issue. It's these deep dives that get us all talking about what we do to protect our secrets. I just hate when the real message gets lost in the headline in the local paper. By the way, the headline for the Globe article was "Please do not change your password. You were right: It's a waste of your time. A study says much computer security advice is not worth following."

Enough said?

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Microsoft
References show all

Comments

1

JonBays

Thu 06/05/2010 - 09:56

Easy to manage multi factor authentication and simple PIN's with strong passwords with simplified single sign on for the end users with proper role based access controls built in to a priveledge and access management system that HR and IT can easily manage is whats required. And it's not hard to do it's just that ticking the box and forcing end users tyo mange the business need for multiple complex passwords is cheaper in the short term and meets governance and compliance requirements of strong authentication with just a simple two page written policy even if it's not practical or reasonable for evryone to comply with.

2

Mark

Fri 07/05/2010 - 14:41

.... and why not just use a Finger or Face scan ?

3

KH

Fri 07/05/2010 - 18:09

@JonBays, In total agreement with you on this.

A product called Ardeun Authenticator http://www.ardeun.com addresses these issues and more very well, multi factor authentication, and biometrics.

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: authentication, passwords, security
Latest Blog Posts
Whitepapers
  • HP Managed Print Services solutioning methodology
    Many organisations launch initiatives to increase the efficiency of their imaging and printing environment—only to quickly find that maintaining those improvements is the real challenge. Sustainable, long-term efficiency gains require that imaging and printing be approached as part of your organisation’s overall IT strategy. Read more.
    Learn more »
  • Poster: Cisco Unified Fabric - Infrastructure for Traditional, Virtualised, and Cloud-based Environments
    Cisco Unified Fabric Switching at a glance - view the product portfolio, features and key benefits. Download this free data centre poster.
    Learn more »
  • High Availability with Oracle Database 11g Release 2
    In this paper, we review the common causes of application downtime and discuss how technologies available in the Oracle Database can help avoid costly downtime and enable rapid recovery from unplanned failures and also minimize impact from planned outages. We also highlight new technologies introduced in Oracle Database 11g Release 2 that enable businesses to make their IT infrastructure even more robust and fault tolerant, maximize their return on investment on high availability infrastructure, and provide better quality of service to users.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments