Talk With an Expert

Password Protection: Is This the Best We Can Do?

Password Protection: Is This the Best We Can Do? (PDF, 2.07MB)Published: 20 Aug, 2001
Created by:
SANS Institute
SANS Institute

More often than not, the last barrier between the 'outside world' and most computer systems is some kind of password authentication. While passwords are practically ubiquitous in modern computer systems numerous deficiencies associated with passwords present a critical challenge to network security professionals. If an attacker is able to determine a valid username and password to a computer system they will be able to impersonate the valid user and access the system. Since valid credentials are presented these intrusions often go unnoticed. There are numerous problems that can make password authentication a poor line of defense including weak passwords improper password storage and passwords that are captured by eavesdropping on network traffic. These problems can lead to unauthorized access of computer systems and potentially the compromise of important data.

Meet the expert

SANS Institute
SANS Institute

SANS Institute

Launched in 1989 as a cooperative for information security thought leadership, it is SANS’ ongoing mission to empower cyber security professionals with the practical skills and knowledge they need to make our world a safer place.

Read more about SANS Institute