msmemory_archive: (Default)
msmemory_archive ([personal profile] msmemory_archive) wrote2009-04-08 02:29 pm

(no subject)

If you're going to implement a strong, mandatory, inconvenient policy, it would sure be a good idea to issue a memo, or an all-staff email, or post it on the intranet.

Having to have our IS guy visit each person in the whole site to explain that their computer was locked while they were in the restroom or at lunch, and it will lock itself after 15 minutes of inactivity henceforth, just stinks, for us and for the hapless IS guy. (It also lends itself to people choosing the shortest, weakest passwords they can get away with, if they have to log in several times a day.)

[identity profile] tashabear.livejournal.com 2009-04-08 06:41 pm (UTC)(link)
We have to do that in the military, except that we also have to use our ID cards to log in. We get to use a PIN, though.

It's lots of fun when you get to the gate in the morning and realize that you left your ID in your computer the previous night.

[identity profile] learnedax.livejournal.com 2009-04-08 07:44 pm (UTC)(link)
You know, we also just started doing that, with no explanation at all. I wonder whether it's some new mis-feature that's being pushed by MS...

[identity profile] ilaine-dcmrn.livejournal.com 2009-04-08 08:21 pm (UTC)(link)
Wow, if we implemented something with that kind of customer impact with no notice our eyebrows would be singed back to our collarbones.

[identity profile] cvirtue.livejournal.com 2009-04-08 08:24 pm (UTC)(link)
I'm not an infosec person, but it seems to me that if a company is going to have this sort of security paranoia, then 15 minutes is *too long.*

So as well as being annoying, stupidly implemented, etc, it may also be too lax to be useful.

[identity profile] corwyn-ap.livejournal.com 2009-04-08 11:59 pm (UTC)(link)
Why would you tell everyone at once? That way people can conspire to have the rule overthrown. By having people find out one at a time you spread the discontent around, and by the time a critical mass of people know, many will be resigned to it.

[identity profile] n2mlq.livejournal.com 2009-04-10 12:35 am (UTC)(link)
Or you wind up like me, with good strong passwords, and I keep the auto-lock set for five minutes, three was just a little too short.