Curious warning message: password too secure?
This happened just a couple of weeks ago. I was trying to log in to some remote host to which I haven't connected for some time. So my password had expired and I was asked to change it. Fine. But after changed it, I got this warning saying that my password may be too complex for older windows systems.
This is a warning message, so I am explicitly being made aware that my password is too strong. Knowing that the host is (a) running Windows Server 2003 and (b) not in a domain, let's consider this message for a moment - let's think about the possible meanings of it:
- Should I choose a simpler password because I may access some service on one of these "older" systems with my current credentials?
- Should I choose a simpler password because I may access this service from one of these "older" systems with my current credentials?
Sorry for bashing on Microsoft again, but this is just plain silly.
I know that I am given the choice of keeping compatibility or not, but that fact itself tells me that Windows 2003 Server retains compatibility with such older systems.
Security systems evolve because older ones are found insecure and thus made obsolete. This kind of warning message just leaks that Microsoft prioritises retro compatibility over breaking older APIs, even if important security enhancements are at stake. I guess it is just better for business.
Cheers, PJ.
No comments:
Post a Comment