Commentary

Keith Ferrell
 

Looking For A Password? Look Under A Keyboard

How many of your employees are keeping passwords, log-ins and other information on sticky notes under their keyboards? Easy enough to find out.

How many of your employees are keeping passwords, log-ins and other information on sticky notes under their keyboards? Easy enough to find out.There's a great 1938 Sammy Fain/Irvng Kahal standard called "I'll Be Seeing You," whose most haunting lyric includes the words "In all the old familiar places." (Nice Sinatra/Tommy Dorsey version here.)

Want to see the "old familiar places" for passwords and other sensitive information in your employees' workspaces? Take a look under their keyboards.


More SMB Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

And on the backs of monitors, the bottoms of desk drawers, inside the drawers themselves, pretty much anywhere that sensitive information can be "hidden in plain sight."

Time to take a password-focused look around the workplace.

Don't be surprised at what you find. I was in a small business recently and passed a work cubicle which was notable for its neatness, orderliness... and the 3-ring notebook whose spine bore the printed label PASSWORDS, ETC.

None of this is new, of course. Right in the middle of a good 2002 Symantec piece on passwords you'll find this:

"...exercise extreme caution when writing down or storing passwords. Stories of hackers obtaining passwords through shoulder-surfing and dumpster diving are not urban myths, they are real. Users should resist the temptation to write down passwords on Post-It notes stuck to their monitors or hidden under their keyboards."

Passing time doesn't dim the appeal of those "old familiar places, though. Nor evidently, does security professionalism. A few years ago security firm Cyber-Ark surveyed a couple of hundred IT professionals, and in the course of finding out just how much snooping they were doing into employees' private files (lots), they found out just how many security pros in their survey base were writing passwords on Post-its. Answer: also lots.

As Cyber-Ark reported: "More than half of people still keep their passwords on a Post-it note, in spite of all the education and reminders to do differently. What's shocking about this year's annual survey was that the 50% number now applies to IT Professionals as well!" (The passwords the pros Post-it-ized included administrative passwords, as well as individual ones.

Not that the sticky note approach doesn't have its adherents.

Last year, F-Secure blogger Sean Sullivan made a strong case for writing strong passwords down, and for writing them down on Post-its. The trick was that you don't write the whole password down. Read about this approach in detail here.

The post closed with a familiar refrain:

"Don't put the Post-it on your monitor! And not on the underside of your keyboard either… everyone's familiar with that location too."

But Sullivan also had some solid advice on where to store the written password: your wallet.

Think about it: people keep things in their wallets that they really care about protecting, however they feel about their passwords. Good tip, worth passing along.

Take a look around your workplace's "old familiar places" sometime soon. Just don't be surprised what you find there.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links