14

We developed this website plus custom CMS for an university. I told them that we could host the entire system and take care of it for an annual fee but they decided to host it in house because security. The IT guy didn't ask for my public key, he sent me a password. By email. Less than 8 characters long. Only recognizable abbreviated words. And a dot.

Comments
  • 0
    Fml.. #facepalm
  • 0
    There might be a bit of logic in that! Higher entropy in four English words than in a mesh of numbers and symbols. But 8 characters isn't long enough for a password!
  • 1
    Yeah, my important passwords are made of some random words, but in this case you can count just three elements: two abbreviated words and a dot. And what makes it worst is that the two abbreviated words are related to the website.

    Besides that don't you think that it is 2016 and all sysadmins should disable password log ins on SSH?
Add Comment