Search DominoPower's 11,441 Lotus-related article archive 
Home
EasyPrint
News details Click here for the RSS feed's XML code. This is not a browser URL.
Articles-only Click here for the RSS feed's XML code. This is not a browser URL.
Twitter Feed Click here for the Twitter feed.
The security of common sense (continued)

So, if you have a six-character password and remember to change it once every 150 or so years, you'll stay well ahead of any potential hackers. Really, this is why outside attacks are so rare, because the time involved is insurmountable. This does shine the spotlight on the LotteryHack though. The LotteryHack bypasses the Great Divide because it works locally. This is what scared all those security people when they learned that hashed Internet passwords don't contain a salt. It means a user can take that password locally and try to hack it. Without having to connect to a network, you can crack passwords thousands of times faster than what was described above.

Still, 1000 times isn't that big of a deal when it means that you would still need to wait a half a year to crack one password. The technology isn't here yet for it to matter too much, but someday there will be quad-processor, 800 terahertz machines that will be able to rip passwords apart in seconds. That's why it's of paramount importance that you at least force the enemy to cross a network to reach you.

Lotus has provided a means in R4.x to strongly encrypt HTTPPasswords, which would make LotteryHack useless and force people to attack via your network. There's an action in the NAB/Domino Directory called, Upgrade to More Secure Internet Password Format. This will add a salt to the HTTPPassword and is highly recommended. In R5, you can default all passwords created strong encryption by changing the setting, Use More Secure Internet Passwords in the Directory Profile. Remember that Domino Directories often replicate and be sure that all replicas have the strongly encrypted version of the passwords-having one Domino Directory out there still containing weak passwords defeats the purpose of encrypting any of them.

Brother against brother
We've detailed the various aspects of the third most common form of security breach, so now for the second most common. This category is exponentially more likely to visit your company than the third and comprises violations by disgruntled employees, disgruntled ex-employees, lazy employees, and bad programming.

This is the area that your security department should be concentrating on. Not only are these "hackers" informed about what information to take and how to take it, they often have direct access to do so. This magazine has published many great articles on security measures that can help. However, there are some general things I'd like to point out.

Ignorance of the law is an excuse
Make sure employees know what they're allowed and not allowed to do. Reminders that company email is company property and that its uses should be limited to "x, y, and z" will make sure people know their limitations. There's a fine line between the merely curious and those attempting to harm your company. Most employees, if they know they could jeopardize their standing in the company through certain actions, won't take them. They often don't know what's off-limits, though.


« Previous  ·  1  ·  2  ·  3  ·  4  ·  5  ·  6  ·  7  ·  8  ·  9  ·  10  ·  Next »
Other articles you might like
Home > Strategies > Security (19 articles)
   Incident report: denial of service attack against ConnectedPhotographer.com
   Centralised email encryption at the Domino server level
   Analysis: Spying Chinese temptress steals senior Brit's BlackBerry
Get Weekly Email Updates
Subscribe to our regular weekly email newsletter. It's packed with tips, reviews, deep analysis, and the latest news.
 
Recent DominoPower Articles
Application development, William Shatner, and the origin of the universe
Learn Domino Designer 8.5 for free
The (near) future of Sametime, Quickr, Connections, and Symphony
Inside the IBM Innovations lab
Lotusphere 2010: Hot fixes and cool news for Notes, Domino, and LotusLive
Lotusphere 2010: mobility and collaboration
2010: A Lotusphere of change
Latest Lotus Headlines
Xpages not loading? JVM errors? - Solution
How to implement an iCalendar feed into your Notes calendar with XPages
DWA Hotfixes for Domino 8.5.1FP1 - A Gotcha
IBM Adds DB2 to Lotus Foundations SMB Package
SNTT : XPages onclick Ghosts in the machine
Ports used by Lotus Sametime 8.5 servers
Exploring a Domino Date Bug
>> Read all the news
More from the ZATZ journals
Computing Unplugged: The iPad defenders have spoken
David Gewirtz Online: CNN commentary and analysis
OutlookPower: More about disappearing text
-- Advertisement --

Learn Notes and Domino 8 at your place and pace!
Learn Notes and Domino in your office and/or home! TLCC's highly acclaimed distance learning courses for users, developers, and admins will enhance your career and your resume.

The many included activities and demos will make you a pro! Expert instructor help is a click away.

Click here to try a FREE demo course!!

-- Advertisement --

Integrate your Notes Applications with Microsoft Office and Symphony
Integra for Notes Integrates Microsoft Office and/or IBM Lotus Symphony
Requires NO change to the design of the appliation or Installations of DLL's and EXE's
  • Integra is a ready to use solution, enhance static reports with Excel data analysis, pivot tables, macros
  • User friendly aproach, using a point and click access to features
  • Reports from any Lotus Notes databases
  • Runs reports through a Notes client, web browser and scheduled basis
  • Allows use of LotusScript for advanced data manipulation
  • Enables self service reporting capabilities to end-users


Learn more at www.integra4notes.com.
ZATZ Home  ·  News  ·  Back Issues  ·  Credits/Trademarks ·  Link To Us
Copyright © 1998-2010, ZATZ Publishing. All rights reserved worldwide.
Editor's Login