How many passwords do you have for work?

Soldato
Joined
15 May 2010
Posts
10,111
Location
Out of Coventry
Logging on to my IT today, I started thinking about how many passwords I have to remember just to do my day job...

I have:

Head office:
Encryption
Log on
Phone
VPN
Document passwords x2

Client 1:
Encryption
Log on
Phone
VPN
Custom App
Document passwords x2

Client 2:
Log on x2
Custom App
Phone
VPN

For a total of 19 separate passwords (+ company card pin), I'll use about 14-15 of them in a given week.
Does anyone have more to remember for work?
 
Out of curiosity, how many of you with loads of passwords create them using algorithms?

hglYS3E.png


I use this to generate all of mine, I wouldn't be able to remember as many streams of gibberish otherwise.
 
I have to use an RSA token for remote log in + password

I forgot about RSA tokens, I've got two of them too :p

Can't use a password manager either as its spread across 4 unique networks.

For those of you with 100's of passwords, I presume your in support? What actually the point of so many?
 
When I've seen password-mania, it usually arises when workstations, servers, software, etc. aren't connected, or aren't properly connected, to a directory service. So you have two options: use one password for everything, but when you need to change it (eg. expiry or security breach) you have to change it in all of those different locations; or use different passwords for everything, which is harder to remember but means that the passwords can be expired/changed/etc. individually.

Public sector. They appear to have procured many bespoke systems over many years and each has its own login. To me it makes sense to consolidate them or use publicly available alternatives but I imagine the answer to that now would be "don't have the budget".

We do have a local password manager but it only works for certain intranet applications on IE. We have Chrome but add-ons are blocked so no Lastpass :rolleyes:

Yeah I've just realised the stupidity of my question, I was thinking just in terms of user and remote admin, I forgot about servers, firewalls, switches, legacy, UPS etc... I can see how it adds up.
 
Hypothetically If one of our bosses were to come across this thread how worried would you be?

Myself not at all I've given nothing away!:p

All I've said is that my clients have different networks to each other, some use encryption, and that there are other passwords for other stuff, some VPNs exist and they are adequately protected, and that I use a good method of making passwords. This is not a lot of information. My bosses wouldn't care - and I work for a security firm :p.

If the question was, do you re-use passwords and people were saying yet, all my passwords are HarryPotterIsGr8! then the company would be pretty peeved.
 
Back
Top Bottom