F34r My L33t P455w0rd 5ki11z!!!1!

I just received the following password policy. This is legitimate. Not made up:


****

The following network password policy is in place:

* Passwords must be at least six characters long.

* Passwords may not contain your user name or any part of your full name.

* The past five (5) passwords cannot be used.

* Passwords must contain characters from at least three of the following four classes:

Description Examples
English upper case letters A, B, C, … Z
English lower case letters a, b, c, … z
Westernized Arabic numerals 0, 1, 2, … 9
Non-alphanumeric (“special characters”) Punctuation marks and other symbols

Password creation recommendations:

1. Don’t use a word that can be found in any dictionary, in any language.

2. Don’t use personal information such as your phone number, birthday, cat’s name, or mother’s name.

3. Select a password that is easy for you to remember but difficult for anyone else to guess.

4. Sometimes, people combine several words together and form a phrase that is not in any dictionary. For example, combine the words ate, my, and hat to form the password 8my$Hat.

5. Other examples: L33t3r – 2Born0t2b – B3myGu3st – 43v3r;Yrs

** Note:** Remote users will need to make sure they log into the network at least every 30 days so that their network password does not expire. A VPN connection is required for remote users to log into the network to make password changes.

Please contact the Help Desk if you have any questions or problems.
****

In other words, all users are required to create a password that is most succeptible to people who [Sp34k L33t](http://www.megatokyo.com/index.php?strip_id=9). I.e. The widest possible potential pool of noobie hackers. W00t.

Unknown's avatar

Author: KB French

Formerly many things, including theology student, mime, jr. high Latin teacher, and Army logistics officer. Currently in the National Guard, and employed as a civilian... somewhere

6 thoughts on “F34r My L33t P455w0rd 5ki11z!!!1!”

  1. Yeah, they did that at USIS too. Only I don’t know that they gave that detailed of rules; I wasn’t there.

    But the default was $Password and most people just left it like that. Ha. Works about as well as 12345 did!

    Like

  2. This is similar to the password policy at many companies. I’ve read that complex password policies like this mean that many people write down there password; if someone has physical access to the cube, the policy might make it easier for individuals to access the network.

    Ph34r passwd pol1cies, I guess you could say.

    http://www.smat.us/sanity/ is interesting reading.

    Like

Leave a reply to difrench Cancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.