18 January 2018

IT Security 101: don't put your password on a post-it note!


A photograph, taken by Associated Press back in July 2017, shows Hawaii Emergency Management Agency’s operations officer in front of a bank of computer screens at its headquarters in Honolulu. But if you look past the colourful Hawaiian shirt, and zoom in on the computers used to monitor potential hazards, you’ll see a solitary Post-it note - detailing their password!

To be honest, I've seen worse... No names, no pack drill, but years ago a director of a major company passed me a laptop case which had a laptop with installed corporate VPN software. Also in the bag were a smartcard reader, with the smartcard in it & the password on a post-it note stuck to the reader! This is literally everything required to externally breach a corporate network - at director level!

Post-it notes are great, but puhleaze - don't use them for passwords!!! 


No comments:

Post a Comment