7
My coworker's sticky note habit exposed our biggest password flaw
Last week I saw Sara at my office in Austin with a yellow sticky note under her keyboard that had our CRM password on it. I called her out gently and she said, 'it's the only way I remember this thing.' That got me thinking about how we force people to use 14 character gibberish that no human can actually memorize. So I looked at our office and found 4 more people doing the same thing, all with different critical logins. Has anyone else pushed back on strict password rules that just make people write stuff down?
1 comments
Log in to join the discussion
Log In1 Comment
sandra_moore304d ago
Do you have a password manager at your company? That's honestly the FIRST thing I'd push for, because sticky notes are just a symptom of a bad system. I've been through this exact thing at my last job, and what worked was getting our IT guy to let us use a shared vault with a master password that was actually memorable, like a phrase with numbers. The gibberish passwords never get typed by humans anymore, they just autofill, and the only thing you need to remember is that one master key. Also, don't shame people for the sticky notes, that just makes them hide them better. Get management to pay for the tool, it's cheaper than a data breach, and tell them that from someone who's seen the aftermath of a hacked CRM. But seriously, if the tool isn't an option, suggest they use a code system like writing "blue elephant" and keeping the real password in a locked drawer, that's better than dead center under the keyboard.
6