
This is a warning message, so I am explicitly being made aware that my password is too strong. Knowing that the host is (a) running Windows Server 2003 and (b) not in a domain, let's consider this message for a moment - let's think about the possible meanings of it:
- Should I choose a simpler password because I may access some service on one of these "older" systems with my current credentials?
- Should I choose a simpler password because I may access this service from one of these "older" systems with my current credentials?
Sorry for bashing on Microsoft again, but this is just plain silly.
I know that I am given the choice of keeping compatibility or not, but that fact itself tells me that Windows 2003 Server retains compatibility with such older systems.
Security systems evolve because older ones are found insecure and thus made obsolete. This kind of warning message just leaks that Microsoft prioritises retro compatibility over breaking older APIs, even if important security enhancements are at stake. I guess it is just better for business.
Cheers, PJ.
No comments:
Post a Comment