Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc.

Go Back   Reseller Hosting, Shared Hosting, Dedicated Hosting by Vortech Inc. > >>Network Information & News and Announcements > News and Announcements
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

News and Announcements This is where you can read announcements regarding Vortech Inc.

Reply
 
Thread Tools Display Modes
  #1  
Old 09-11-2003, 06:08 PM
shwhite
Guest
 
New Password Policy

Due to some recent security breakdowns with our customer and their end-user accounts, we are now implement a stricter policy when it comes to password creation. All passwords are now required to have one number, one capital letter, one lower-case letter and cannot be or contain the username. Also, all passwords must be from 6 to 12 characters.
Reply With Quote
  #2  
Old 09-11-2003, 06:18 PM
Garreg's Avatar
Garreg Garreg is offline
Resident Optimist
Vortech Inc. Customer
 
Location: UK - Mon to Fri. Mars - all Weekend
?

From when ... i.e. will existing passwords cease to function after XXX date? hence we (and all our clients) needs to change them by them?
__________________
Regards to all
Reply With Quote
  #3  
Old 09-11-2003, 06:24 PM
jmbeach's Avatar
jmbeach jmbeach is offline
mistra know it all
Vortech Inc. Customer
 
Location: San Diego
I'm guessing it's only for new passwords. My guess is it would be nearly impossible to get all users to change existing passwords

Also, this doesn't affect email passwords, right? They currently only require a minimum of 5 characters.
Reply With Quote
  #4  
Old 09-11-2003, 06:27 PM
Bladesnitz
Guest
 
It only affects new passwords. People currently with weak passwords need to change them as we are considering auditing current passwords due to recent security concerns.
Reply With Quote
  #5  
Old 09-11-2003, 06:35 PM
Garreg's Avatar
Garreg Garreg is offline
Resident Optimist
Vortech Inc. Customer
 
Location: UK - Mon to Fri. Mars - all Weekend
Phew!!!!!

with in excess of 80 domains - the thought of editing passwords for FTP / CP / email etc.... (as I have diffrent for each) was making me reach for the old whisky jar.....
__________________
Regards to all
Reply With Quote
  #6  
Old 09-11-2003, 06:40 PM
Allen Allen is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Send a message via AIM to Allen
Does the new rule also apply to databases?

Allen
Reply With Quote
  #7  
Old 09-11-2003, 06:40 PM
jmbeach's Avatar
jmbeach jmbeach is offline
mistra know it all
Vortech Inc. Customer
 
Location: San Diego
Matt, can you also confirm which passwords will need to take on the new requirements? As I said before, email passwords are currently at 5 characters, and typically people don't want strong passwords on their email accounts - makes them too hard to remember.

Is this only for CP/FTP?
Reply With Quote
  #8  
Old 09-11-2003, 06:40 PM
somereseller's Avatar
somereseller somereseller is offline
Usability everywhere
Vortech Inc. Customer
 
Location: mars
Thank you for taking these kind of issues seriously!
Reply With Quote
  #9  
Old 09-11-2003, 06:45 PM
Bladesnitz
Guest
 
I believe mail passwords are affected as well. All other passwords are definitly affected.

You should ALWAYS use a strong password. They aren't necessarily hard to remember. Your other alternative is to get your stuff hacked, deleted, and if our server's are damaged, YOU are responsible.
Reply With Quote
  #10  
Old 09-11-2003, 06:52 PM
dwhite dwhite is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Thank you for doing this guys. I STRONGLY support this decision, and have been making my customers use an even more stringent policy for the last three years.

For those of you who are concerned about the admittedly daunting task of reviewing and updating passwords for many domains, I suggest you look on it as a bit of insurance against breakins because of weak passwords. The havoc and downtime that can be caused could take you far longer to recover, plus it can be a PR nightmare.

For stuff like this, I look at it as an opportunity to make a positive contact with my customer, and assuring them that I am looking out for their security. Everytime I do it, I get either more work or a surge of referrals.

Just my 2cp =)

EDIT: To use a good online resource for relatively strong password generator, go to http://www.winguides.com/security/password.php
__________________
Regards,

Dan W.

Sign over a SysAdmin's desk: "Just because you are paranoid, doesn't mean they are not out to get you!!"
Reply With Quote
  #11  
Old 09-11-2003, 07:26 PM
Brasil Brasil is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
hehe...you guys are up to soooo many complaints!!!

"To have one number, one capital letter, one lower-case letter and cannot be or contain the username"

I can just see people going "what´s that again???"

or

A flood of complaints saying "what´s wrong with the cp, it doesn´t work, it gives me an error..."

And by the fifth message they click on to it.

Honestly, what seems simple here is just wild talk out there. But I guess we´ll have to configure an autoresponse for this sure same re-ocurring question.

Never mind...we´ll make it look good, as dwhite said.
Reply With Quote
  #12  
Old 09-11-2003, 08:07 PM
Bladesnitz
Guest
 
Well, it should tell you right on the page what it needs to be. Look in the status bar. If your javascript works right, it should tell you.
Reply With Quote
  #13  
Old 09-11-2003, 09:10 PM
TicoGrande TicoGrande is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: San Jose, Costa Rica
I would like to make a strong suggestion.

This new password policy is GOOD, but I notice there has been no change whatever to the Signup Form text content.

It still says "The password should be at least 5 characters long.

For security reasons it is recommended to use a combination of small letters, caps and numbers. After the registration, you can change the password at any time. For security purposes it is recommended that you do so on a regular basis."

If a bad password is entered, a pop up tells the real story, but I'd like to see the TEXT part corrected to not waste customer's time.

Also, they may not bother to read carefully the wording in the pop-up (which is adequate, BTW... but since it is wrong in the text area... wel you get the point)

Can you please make that change to the main text area?

Thanks

Tim
Reply With Quote
  #14  
Old 09-11-2003, 09:12 PM
TicoGrande TicoGrande is offline
Vortech Inc. Customer
Vortech Inc. Customer
 
Location: San Jose, Costa Rica
Note to Alan

Yes... Databases are affected.
Reply With Quote
  #15  
Old 09-11-2003, 09:30 PM
javier011's Avatar
javier011 javier011 is offline
Business World
Vortech Inc. Customer
 
Quote:
Originally posted by TicoGrande
I would like to make a strong suggestion.

This new password policy is GOOD, but I notice there has been no change whatever to the Signup Form text content.

It still says "The password should be at least 5 characters long.

For security reasons it is recommended to use a combination of small letters, caps and numbers. After the registration, you can change the password at any time. For security purposes it is recommended that you do so on a regular basis."

If a bad password is entered, a pop up tells the real story, but I'd like to see the TEXT part corrected to not waste customer's time.

Also, they may not bother to read carefully the wording in the pop-up (which is adequate, BTW... but since it is wrong in the text area... wel you get the point)

Can you please make that change to the main text area?

Thanks

Tim


yup, this will need to be done!
__________________
Thank You

Javier
Advertising Websites
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
matrix policy arindra Chit Chat Public 16 07-11-2003 01:14 PM
Policy on Backups mattrix Chit Chat Public 15 06-23-2003 08:45 PM
Downtime refund policy admin News and Announcements 16 06-03-2003 01:19 PM


All times are GMT -5. The time now is 01:49 PM.


Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Vortech Inc. ©2005
Page generated in 0.62250 seconds with 22 queries
[Output: 105.31 Kb. compressed to 96.50 Kb. by saving 8.82 Kb. (8.37%)]