March 31, 2009


Sometimes I wonder why software systems constantly require users to change their passwords.

I suppose they assume we all have an infinite capacity to remember a string of numbers, digits and symbols are repeat that information anytime in the future without ever writing it down anywhere.

But you see, we often do. Most people have written down their passwords until they have memorized them.

I feel this is horribly insecure compared to allowing users to keep their existing passwords until they desire to change them.

March 29, 2009

Banking “security”

So today my bank tells me i’m going to get a new debit card and new debit card number.

Because one of the VISA transaction companies (Heartlland) was broken into and an *unknown* number of card numbers were stolen.

This is not the first time this has happened to me, or the second, or the third, no it’s the fourth time.

The fourth time that i’ve had to go online and change the card number that gets automatically debited for my bills, the fourth time i’ve had to deal with a new PIN number, and the fourth time that i’ve been reminded that even tho banks are piling on more and more complications to your personal login they seem to know nothing about how to protect corporate data.

