Back
ExercisesComplete set

Raccolta completa esercizi

Complete course materials for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Exercises - 1 Authentication - Authorization Computer Security 2018 Question 3 (2 points) We are designing the password policy for an online banking website. Which of the following rule sets is more adequate in your opinion, and why? ● Passwords must be at least 12 characters

Computer SecurityComplete set

Document information

What's included in this study material

Complete course materials for Computer Security in the Computer Engineering degree programme at Politecnico di Milano. The document covers: Exercises - 1 Authentication - Authorization Computer Security 2018 Question 3 (2 points) We are designing the password policy for an online banking website. Which of the following rule sets is more adequate in your opinion, and why? ● Passwords must be at least 12 characters

Import quality: text was extracted directly from the original document.

Extracted content from the document

Representative passages recognised in different parts of the material. The full extracted text remains available to search, while this compact preview makes the page easier to read.

Page 1

Exercises - 1 Authentication - Authorization Computer Security 2018 Question 3 (2 points) We are designing the password policy for an online banking website. Which of the following rule sets is more adequate in your opinion, and why? ● Passwords must be at least 12 characters long, with at least one lowercase, one uppercase, one number and one special character. Passwords must be changed at least every 30 days and cannot match previous ones. Accounts are locked after 3 wrong attempts. ● Passwords must be at least 8 characters long, and not belong to a dictionary of common passwords. They must be changed at least every 30 days and cannot match previous ones. Accounts are locked after 5 wrong attempts. Question 3 (2 points) We are designing the password policy for an online banking website. Which of the following rule sets is more adequate in your opinion, and why? ● Passwords must be at least 8 characters long, and not belong to a dictionary of common passwords. They must be changed at least every 30 days and cannot match previous ones. Accounts are locked after 5 wrong attempts. Question 3 (2 points) We are designing the password policy for an online banking website. Which of the following rule sets is more adequate in your opinion, and why? ● Passwords must be at least 12 characters long, with at least one lowercase, one uppercase, one number and one special character. Passwords must be changed at least every 30 days and cannot match previous ones. Accounts are locked after 3 wrong attempts. This seems stronger, because it enforces long (against bruteforcing), non-reused (against stealing) passwords and mitigates bruteforcing. However, it will lead users to write down passwords. Question 3 (2 points) We are designing the password policy for an online banking website.…

Preview

First page of the document.

First page: Raccolta completa esercizi