# Network Security Experts: Frequent Password Changes

**URL:** <https://boards.straightdope.com/t/network-security-experts-frequent-password-changes/291020>\
**Category:** Factual Questions\
**Created:** [February 20, 2005, 1:55pm UTC](https://boards.straightdope.com/t/network-security-experts-frequent-password-changes/291020 "2005-02-20T13:55:57Z")\
**Posts on this page:** 2\
**Page:** 2

<div class="post-metadata">

**Author:** ![rjk](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@rjk](https://boards.straightdope.com/u/rjk)\
**Post date:** [February 21, 2005, 3:24pm UTC](https://boards.straightdope.com/t/network-security-experts-frequent-password-changes/291020/21 "2005-02-21T15:24:17Z")

</div>

> [@Futile Gesture](#):
>
> … What is unforgivable though, and I hate, hate, hate systems that do this are passwords that are case sensitive. It really does make getting them right twice as hard. …

It does make getting them right a little harder, but it also makes cracking them a _lot_ more than twice as hard. I can see from your post that you can use the shift key appropriately, so why is it so hard to use it in a password? A few years ago, one of our network guys ran a simple dictionary-based cracker against our password files, and got over half of them. We soon changed to a system that required mixed case and some non-alpha characters, and had hardly any problems.  
[/rant]

I agree that writing down a password and keeping it in your wallet is a good way to remember it and keep it secure; I sometimes recommended that to users when I was working helpdesk. If your office is as secure as **micco** ’s, the sticky on the monitor is fine, but that leaves you doing your own cleaning. :dubious:

---

<div class="post-metadata">

**Author:** ![micco](https://avatars.discourse-cdn.com/v4/letter/m/5f8ce5/32.png) [@micco](https://boards.straightdope.com/u/micco)\
**Post date:** [February 21, 2005, 3:45pm UTC](https://boards.straightdope.com/t/network-security-experts-frequent-password-changes/291020/22 "2005-02-21T15:45:46Z")

</div>

> [@rjk](#):
>
> If your office is as secure as **micco** ’s, the sticky on the monitor is fine, but that leaves you doing your own cleaning. :dubious:

Home office, I don’t have to go to the corporate office more than a few times a year. As I said, this doesn’t apply to everyone but that’s the whole point - most security rules should not be applied to everyone without thought to individual circumstance.

[Previous page](https://boards.straightdope.com/t/network-security-experts-frequent-password-changes/291020.md?page=1)
