Document information
- University
- Politecnico di Milano
- Degree programme
- Computer Engineering
- Subject
- Computer Security
- Classification
- Exercises · Complete set
- Original format
- Text
- Searchable text
Complete course materials for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Exercises - 1 Authentication - Authorization Computer Security 2018 Question 3 (2 points) We are designing the password policy for an online banking website. Which of the following rule sets is more adequate in your opinion, and why? ● Passwords must be at least 12 characters
Complete course materials for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Exercises - 1 Authentication - Authorization Computer Security 2018 Question 3 (2 points) We are designing the password policy for an online banking website. Which of the following rule sets is more adequate in your opinion, and why? ● Passwords must be at least 12 characters
Import quality: text was extracted directly from the original document.
Representative passages recognised in different parts of the material. The full extracted text remains available to search, while this compact preview makes the page easier to read.
Exercises - 1 Authentication - Authorization Computer Security 2018 Question 3 (2 points) We are designing the password policy for an online banking website. Which of the following rule sets is more adequate in your opinion, and why? ● Passwords must be at least 12 characters long, with at least one lowercase, one uppercase, one number and one special character. Passwords must be changed at least every 30 days and cannot match previous ones. Accounts are locked after 3 wrong attempts. ● Passwords must be at least 8 characters long, and not belong to a dictionary of common passwords. They must be changed at least every 30 days and cannot match previous ones. Accounts are locked after 5 wrong attempts. Question 3 (2 points) We are designing the password policy for an online banking website. Which of the following rule sets is more adequate in your opinion, and why? ● Passwords must be at least 8 characters long, and not belong to a dictionary of common passwords. They must be changed at least every 30 days and cannot match previous ones. Accounts are locked after 5 wrong attempts. Question 3 (2 points) We are designing the password policy for an online banking website. Which of the following rule sets is more adequate in your opinion, and why? ● Passwords must be at least 12 characters long, with at least one lowercase, one uppercase, one number and one special character. Passwords must be changed at least every 30 days and cannot match previous ones. Accounts are locked after 3 wrong attempts. This seems stronger, because it enforces long (against bruteforcing), non-reused (against stealing) passwords and mitigates bruteforcing. However, it will lead users to write down passwords. Question 3 (2 points) We are designing the password policy for an online banking website.…
First page of the document.