{"id":26717,"date":"2016-10-10T09:14:30","date_gmt":"2016-10-10T07:14:30","guid":{"rendered":"https:\/\/mamchenkov.net\/wordpress\/?p=26717"},"modified":"2016-10-10T09:14:30","modified_gmt":"2016-10-10T07:14:30","slug":"yet-another-bit-on-security","status":"publish","type":"post","link":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/","title":{"rendered":"Yet another bit on security"},"content":{"rendered":"<!-- google_ad_section_start -->\n<p>Here are a couple of interesting articles from the last few days on <a href=\"http:\/\/slashdot.org\">Slashdot<\/a>.<\/p>\n<p>First, comes in a very non-surprising survey saying that &#8220;<a href=\"https:\/\/news.slashdot.org\/story\/16\/09\/23\/2330226\/40-percent-of-organizations-store-admin-passwords-in-word-documents-says-survey\">40 percent of organizations store admin passwords in Word documents<\/a>&#8220;. \u00a0Judging from my personal experiences in different companies, I&#8217;d say this number is much higher if you extend the Word documents to Excel spreadsheets and plain text files. \u00a0I think pretty much every single company I&#8217;ve worked at used such common files for admin password storage (at least at some point).<\/p>\n<p>&#8220;Why or why?!!!&#8221;, the security concerned among you might scream. \u00a0Well, I think there are two reasons for this. \u00a0The first one is that password management is complicated. \u00a0There are tools that help with this, but even those are rarely easy to use. \u00a0Storing the passwords in a secure, encrypted storage is one thing. \u00a0But, how do you share them with just the right people? How do you trust the tool? What happens if the file gets corrupted, the software updates, the license expires, or the master password is lost? \u00a0The risk of losing admin access to all your equipment and accounts is scary. \u00a0On top of that, there is the issue of changing passwords (especially when people leave the company) &#8211; not a simple job if you have a variety of accounts (hardware, software, services, etc) and a lot of people who have a varying degree of access. \u00a0Or automation scripts that need access to perform large scale operations. \u00a0Personally, I don&#8217;t think this problem has been solved yet.<\/p>\n<p>The second reason is in this other Slashdot post &#8211; &#8220;<a href=\"https:\/\/it.slashdot.org\/story\/16\/09\/23\/1831214\/sad-reality-its-cheaper-to-get-hacked-than-build-strong-it-defenses\">Sad Reality: It&#8217;s Cheaper To Get Hacked Than Build Strong IT Defenses<\/a>&#8220;. \u00a0This is very true as well. \u00a0A simple firewall and a strong password policy is often more than enough for many organizations. \u00a0The risks of compromise are low. \u00a0In those cases where it does happen, you&#8217;d often get some script kiddie consequence like a Bitcoin mining app or affiliate links spread across your website. \u00a0Both are quite easy to detect and fix. \u00a0Is it worth investing hundreds of thousands in equipment and personnel to prevent this? For many companies it is not.<\/p>\n<p>The fact of the matter is that a lot of people don&#8217;t really care about security or privacy on the personal level, and that then translates into the organizational mentality as well.<\/p>\n<p>Just think about people leaving in all those high crime areas. \u00a0Some of them think the risk is worth it &#8211; maybe then can make more money there or have a more exciting life. \u00a0Some of them simply can&#8217;t afford to move anywhere. \u00a0That&#8217;s very similar to the digital security, I think. \u00a0Some don&#8217;t care and prefer to run the risk, saving the money on protection. Some simply can&#8217;t afford to have a decent level of security.<\/p>\n<!-- google_ad_section_end -->\n","protected":false},"excerpt":{"rendered":"<!-- google_ad_section_start -->\n<p>Here are a couple of interesting articles from the last few days on Slashdot. First, comes in a very non-surprising survey saying that &#8220;40 percent of organizations store admin passwords in Word documents&#8220;. \u00a0Judging from my personal experiences in different companies, I&#8217;d say this number is much higher if you extend the Word documents to &hellip; <a href=\"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Yet another bit on security<\/span><\/a><\/p>\n<!-- google_ad_section_end -->\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"Yet another bit on security #security #business #technology","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false,"_links_to":"","_links_to_target":""},"categories":[1,133,62,1334],"tags":[1968,1117,200],"keyring_services":[],"class_list":["post-26717","post","type-post","status-publish","format-standard","hentry","category-general","category-sysadmin","category-technology","category-web-work","tag-business","tag-research","tag-security"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"Here are a couple of interesting articles from the last few days on Slashdot. First, comes in a very non-surprising survey saying that &quot;40 percent of organizations store admin passwords in Word documents&quot;. Judging from my personal experiences in different companies, I&#039;d say this number is much higher if you extend the Word documents to\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Leonid Mamchenkov\"\/>\n\t<meta name=\"google-site-verification\" content=\"VHvdD0_usx1_4DzKy_QCVcICVgX2EgA2ybELT-wl7kQ\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Leonid Mamchenkov - Life, universe, and everything else\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Yet another bit on security - Leonid Mamchenkov\" \/>\n\t\t<meta property=\"og:description\" content=\"Here are a couple of interesting articles from the last few days on Slashdot. First, comes in a very non-surprising survey saying that &quot;40 percent of organizations store admin passwords in Word documents&quot;. Judging from my personal experiences in different companies, I&#039;d say this number is much higher if you extend the Word documents to\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/mamchenkov.net\/wordpress\/wp-content\/uploads\/2026\/03\/leonid-sailing-beer.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/mamchenkov.net\/wordpress\/wp-content\/uploads\/2026\/03\/leonid-sailing-beer.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t\t<meta property=\"og:image:height\" content=\"1024\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2016-10-10T07:14:30+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2016-10-10T07:14:30+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/MamchenkovBlog\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@mamchenkov\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Yet another bit on security - Leonid Mamchenkov\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Here are a couple of interesting articles from the last few days on Slashdot. First, comes in a very non-surprising survey saying that &quot;40 percent of organizations store admin passwords in Word documents&quot;. Judging from my personal experiences in different companies, I&#039;d say this number is much higher if you extend the Word documents to\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@mamchenkov\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/mamchenkov.net\/wordpress\/wp-content\/uploads\/2026\/03\/leonid-sailing-beer.jpg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/2016\\\/10\\\/10\\\/yet-another-bit-on-security\\\/#blogposting\",\"name\":\"Yet another bit on security - Leonid Mamchenkov\",\"headline\":\"Yet another bit on security\",\"author\":{\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/author\\\/leonid\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/2016\\\/10\\\/10\\\/yet-another-bit-on-security\\\/#articleImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/3cf6df002a284d78fb6e9d8222ca4d102e0832035ed6bc8447008bd234e131a4?s=96&d=identicon&r=g\",\"width\":96,\"height\":96,\"caption\":\"Leonid Mamchenkov\"},\"datePublished\":\"2016-10-10T09:14:30+02:00\",\"dateModified\":\"2016-10-10T09:14:30+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/2016\\\/10\\\/10\\\/yet-another-bit-on-security\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/2016\\\/10\\\/10\\\/yet-another-bit-on-security\\\/#webpage\"},\"articleSection\":\"All, Sysadmin, Technology, Web work, business, research, security\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/2016\\\/10\\\/10\\\/yet-another-bit-on-security\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/category\\\/technology\\\/#listItem\",\"name\":\"Technology\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/category\\\/technology\\\/#listItem\",\"position\":2,\"name\":\"Technology\",\"item\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/category\\\/technology\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/category\\\/technology\\\/sysadmin\\\/#listItem\",\"name\":\"Sysadmin\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/category\\\/technology\\\/sysadmin\\\/#listItem\",\"position\":3,\"name\":\"Sysadmin\",\"item\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/category\\\/technology\\\/sysadmin\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/2016\\\/10\\\/10\\\/yet-another-bit-on-security\\\/#listItem\",\"name\":\"Yet another bit on security\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/category\\\/technology\\\/#listItem\",\"name\":\"Technology\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/2016\\\/10\\\/10\\\/yet-another-bit-on-security\\\/#listItem\",\"position\":4,\"name\":\"Yet another bit on security\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/category\\\/technology\\\/sysadmin\\\/#listItem\",\"name\":\"Sysadmin\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/#person\",\"name\":\"Leonid Mamchenkov\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/2016\\\/10\\\/10\\\/yet-another-bit-on-security\\\/#personImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/3cf6df002a284d78fb6e9d8222ca4d102e0832035ed6bc8447008bd234e131a4?s=96&d=identicon&r=g\",\"width\":96,\"height\":96,\"caption\":\"Leonid Mamchenkov\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/author\\\/leonid\\\/#author\",\"url\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/author\\\/leonid\\\/\",\"name\":\"Leonid Mamchenkov\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/2016\\\/10\\\/10\\\/yet-another-bit-on-security\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/3cf6df002a284d78fb6e9d8222ca4d102e0832035ed6bc8447008bd234e131a4?s=96&d=identicon&r=g\",\"width\":96,\"height\":96,\"caption\":\"Leonid Mamchenkov\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/2016\\\/10\\\/10\\\/yet-another-bit-on-security\\\/#webpage\",\"url\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/2016\\\/10\\\/10\\\/yet-another-bit-on-security\\\/\",\"name\":\"Yet another bit on security - Leonid Mamchenkov\",\"description\":\"Here are a couple of interesting articles from the last few days on Slashdot. First, comes in a very non-surprising survey saying that \\\"40 percent of organizations store admin passwords in Word documents\\\". Judging from my personal experiences in different companies, I'd say this number is much higher if you extend the Word documents to\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/2016\\\/10\\\/10\\\/yet-another-bit-on-security\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/author\\\/leonid\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/author\\\/leonid\\\/#author\"},\"datePublished\":\"2016-10-10T09:14:30+02:00\",\"dateModified\":\"2016-10-10T09:14:30+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/#website\",\"url\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/\",\"name\":\"Blog of Leonid Mamchenkov\",\"description\":\"Life, universe, and everything else\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/mamchenkov.net\\\/wordpress\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Yet another bit on security - Leonid Mamchenkov","description":"Here are a couple of interesting articles from the last few days on Slashdot. First, comes in a very non-surprising survey saying that \"40 percent of organizations store admin passwords in Word documents\". Judging from my personal experiences in different companies, I'd say this number is much higher if you extend the Word documents to","canonical_url":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"VHvdD0_usx1_4DzKy_QCVcICVgX2EgA2ybELT-wl7kQ","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/#blogposting","name":"Yet another bit on security - Leonid Mamchenkov","headline":"Yet another bit on security","author":{"@id":"https:\/\/mamchenkov.net\/wordpress\/author\/leonid\/#author"},"publisher":{"@id":"https:\/\/mamchenkov.net\/wordpress\/#person"},"image":{"@type":"ImageObject","@id":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/#articleImage","url":"https:\/\/secure.gravatar.com\/avatar\/3cf6df002a284d78fb6e9d8222ca4d102e0832035ed6bc8447008bd234e131a4?s=96&d=identicon&r=g","width":96,"height":96,"caption":"Leonid Mamchenkov"},"datePublished":"2016-10-10T09:14:30+02:00","dateModified":"2016-10-10T09:14:30+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/#webpage"},"isPartOf":{"@id":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/#webpage"},"articleSection":"All, Sysadmin, Technology, Web work, business, research, security"},{"@type":"BreadcrumbList","@id":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/mamchenkov.net\/wordpress#listItem","position":1,"name":"Home","item":"https:\/\/mamchenkov.net\/wordpress","nextItem":{"@type":"ListItem","@id":"https:\/\/mamchenkov.net\/wordpress\/category\/technology\/#listItem","name":"Technology"}},{"@type":"ListItem","@id":"https:\/\/mamchenkov.net\/wordpress\/category\/technology\/#listItem","position":2,"name":"Technology","item":"https:\/\/mamchenkov.net\/wordpress\/category\/technology\/","nextItem":{"@type":"ListItem","@id":"https:\/\/mamchenkov.net\/wordpress\/category\/technology\/sysadmin\/#listItem","name":"Sysadmin"},"previousItem":{"@type":"ListItem","@id":"https:\/\/mamchenkov.net\/wordpress#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/mamchenkov.net\/wordpress\/category\/technology\/sysadmin\/#listItem","position":3,"name":"Sysadmin","item":"https:\/\/mamchenkov.net\/wordpress\/category\/technology\/sysadmin\/","nextItem":{"@type":"ListItem","@id":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/#listItem","name":"Yet another bit on security"},"previousItem":{"@type":"ListItem","@id":"https:\/\/mamchenkov.net\/wordpress\/category\/technology\/#listItem","name":"Technology"}},{"@type":"ListItem","@id":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/#listItem","position":4,"name":"Yet another bit on security","previousItem":{"@type":"ListItem","@id":"https:\/\/mamchenkov.net\/wordpress\/category\/technology\/sysadmin\/#listItem","name":"Sysadmin"}}]},{"@type":"Person","@id":"https:\/\/mamchenkov.net\/wordpress\/#person","name":"Leonid Mamchenkov","image":{"@type":"ImageObject","@id":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/#personImage","url":"https:\/\/secure.gravatar.com\/avatar\/3cf6df002a284d78fb6e9d8222ca4d102e0832035ed6bc8447008bd234e131a4?s=96&d=identicon&r=g","width":96,"height":96,"caption":"Leonid Mamchenkov"}},{"@type":"Person","@id":"https:\/\/mamchenkov.net\/wordpress\/author\/leonid\/#author","url":"https:\/\/mamchenkov.net\/wordpress\/author\/leonid\/","name":"Leonid Mamchenkov","image":{"@type":"ImageObject","@id":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/3cf6df002a284d78fb6e9d8222ca4d102e0832035ed6bc8447008bd234e131a4?s=96&d=identicon&r=g","width":96,"height":96,"caption":"Leonid Mamchenkov"}},{"@type":"WebPage","@id":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/#webpage","url":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/","name":"Yet another bit on security - Leonid Mamchenkov","description":"Here are a couple of interesting articles from the last few days on Slashdot. First, comes in a very non-surprising survey saying that \"40 percent of organizations store admin passwords in Word documents\". Judging from my personal experiences in different companies, I'd say this number is much higher if you extend the Word documents to","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/mamchenkov.net\/wordpress\/#website"},"breadcrumb":{"@id":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/#breadcrumblist"},"author":{"@id":"https:\/\/mamchenkov.net\/wordpress\/author\/leonid\/#author"},"creator":{"@id":"https:\/\/mamchenkov.net\/wordpress\/author\/leonid\/#author"},"datePublished":"2016-10-10T09:14:30+02:00","dateModified":"2016-10-10T09:14:30+02:00"},{"@type":"WebSite","@id":"https:\/\/mamchenkov.net\/wordpress\/#website","url":"https:\/\/mamchenkov.net\/wordpress\/","name":"Blog of Leonid Mamchenkov","description":"Life, universe, and everything else","inLanguage":"en-US","publisher":{"@id":"https:\/\/mamchenkov.net\/wordpress\/#person"}}]},"og:locale":"en_US","og:site_name":"Leonid Mamchenkov - Life, universe, and everything else","og:type":"article","og:title":"Yet another bit on security - Leonid Mamchenkov","og:description":"Here are a couple of interesting articles from the last few days on Slashdot. First, comes in a very non-surprising survey saying that &quot;40 percent of organizations store admin passwords in Word documents&quot;. Judging from my personal experiences in different companies, I'd say this number is much higher if you extend the Word documents to","og:url":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/","og:image":"https:\/\/mamchenkov.net\/wordpress\/wp-content\/uploads\/2026\/03\/leonid-sailing-beer.jpg","og:image:secure_url":"https:\/\/mamchenkov.net\/wordpress\/wp-content\/uploads\/2026\/03\/leonid-sailing-beer.jpg","og:image:width":1024,"og:image:height":1024,"article:published_time":"2016-10-10T07:14:30+00:00","article:modified_time":"2016-10-10T07:14:30+00:00","article:publisher":"https:\/\/www.facebook.com\/MamchenkovBlog","twitter:card":"summary_large_image","twitter:site":"@mamchenkov","twitter:title":"Yet another bit on security - Leonid Mamchenkov","twitter:description":"Here are a couple of interesting articles from the last few days on Slashdot. First, comes in a very non-surprising survey saying that &quot;40 percent of organizations store admin passwords in Word documents&quot;. Judging from my personal experiences in different companies, I'd say this number is much higher if you extend the Word documents to","twitter:creator":"@mamchenkov","twitter:image":"https:\/\/mamchenkov.net\/wordpress\/wp-content\/uploads\/2026\/03\/leonid-sailing-beer.jpg"},"aioseo_meta_data":{"post_id":"26717","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2023-07-19 10:03:31","updated":"2026-01-15 12:23:44","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/mamchenkov.net\/wordpress\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/mamchenkov.net\/wordpress\/category\/technology\/\" title=\"Technology\">Technology<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/mamchenkov.net\/wordpress\/category\/technology\/sysadmin\/\" title=\"Sysadmin\">Sysadmin<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tYet another bit on security\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/mamchenkov.net\/wordpress"},{"label":"Technology","link":"https:\/\/mamchenkov.net\/wordpress\/category\/technology\/"},{"label":"Sysadmin","link":"https:\/\/mamchenkov.net\/wordpress\/category\/technology\/sysadmin\/"},{"label":"Yet another bit on security","link":"https:\/\/mamchenkov.net\/wordpress\/2016\/10\/10\/yet-another-bit-on-security\/"}],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack-related-posts":[{"id":22389,"url":"https:\/\/mamchenkov.net\/wordpress\/2014\/08\/15\/tek-security-groups-password-repository\/","url_meta":{"origin":26717,"position":0},"title":"Tek Security Group&#8217;s Password Repository","author":"Leonid Mamchenkov","date":"August 15, 2014","format":"link","excerpt":"Tek Security Group's Password Repository In this repository you will find helpful authentication brute forcing files. These files include known password defaults, usernames, common and specialized dictionaries, etc.","rel":"","context":"In &quot;All&quot;","block_context":{"text":"All","link":"https:\/\/mamchenkov.net\/wordpress\/category\/general\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":16815,"url":"https:\/\/mamchenkov.net\/wordpress\/2012\/10\/08\/microsoft-takes-password-security-to-the-next-level\/","url_meta":{"origin":26717,"position":1},"title":"Microsoft takes password security to the next level","author":"Leonid Mamchenkov","date":"October 8, 2012","format":"link","excerpt":"Microsoft takes password security to the next level I've spotted this link somewhere online, and I think this is funny. Error Message: Your Password Must Be at Least 18770 Characters and Cannot Repeat Any of Your Previous 30689 Passwords The solution is, as always, obtain the latest service pack.","rel":"","context":"In &quot;All&quot;","block_context":{"text":"All","link":"https:\/\/mamchenkov.net\/wordpress\/category\/general\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":18004,"url":"https:\/\/mamchenkov.net\/wordpress\/2013\/04\/14\/wordpress-passwords-and-brute-force\/","url_meta":{"origin":26717,"position":2},"title":"WordPress passwords and brute force","author":"Leonid Mamchenkov","date":"April 14, 2013","format":"link","excerpt":"WordPress passwords and brute force From the man himself: Here\u2019s what I would recommend: If you still use \u201cadmin\u201d as a username on your blog, change it, use a strong password, if you\u2019re on WP.com turn on two-factor authentication, and of course make sure you\u2019re up-to-date on the latest version\u2026","rel":"","context":"In &quot;All&quot;","block_context":{"text":"All","link":"https:\/\/mamchenkov.net\/wordpress\/category\/general\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":16995,"url":"https:\/\/mamchenkov.net\/wordpress\/2012\/12\/07\/the-passwords-are-officially-obsolete\/","url_meta":{"origin":26717,"position":3},"title":"The passwords are officially obsolete","author":"Leonid Mamchenkov","date":"December 7, 2012","format":false,"excerpt":"Slashdot is reporting the story: a cluster of five, 4U servers equipped with 25 AMD Radeon GPUs communicating at 10 Gbps and 20 Gbps over Infiniband switched fabric. Gosney's system elevates password cracking to the next level, and effectively renders even the strongest passwords protected with weaker encryption algorithms, like\u2026","rel":"","context":"In &quot;All&quot;","block_context":{"text":"All","link":"https:\/\/mamchenkov.net\/wordpress\/category\/general\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":29074,"url":"https:\/\/mamchenkov.net\/wordpress\/2018\/12\/10\/php-password-exposed-helper-function\/","url_meta":{"origin":26717,"position":4},"title":"PHP &#8211; Password Exposed Helper Function","author":"Leonid Mamchenkov","date":"December 10, 2018","format":false,"excerpt":"Password Exposed Helper Function is a tiny PHP library that helps checking user passwords against the Have I Been P0wned website API. This is quite common new functionality on many websites and services (see GitHub, for example), which is now available as a quick composer dependency for your PHP projects.","rel":"","context":"In &quot;All&quot;","block_context":{"text":"All","link":"https:\/\/mamchenkov.net\/wordpress\/category\/general\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mamchenkov.net\/wordpress\/wp-content\/uploads\/2018\/12\/password-exposed.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/mamchenkov.net\/wordpress\/wp-content\/uploads\/2018\/12\/password-exposed.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/mamchenkov.net\/wordpress\/wp-content\/uploads\/2018\/12\/password-exposed.png?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/mamchenkov.net\/wordpress\/wp-content\/uploads\/2018\/12\/password-exposed.png?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/mamchenkov.net\/wordpress\/wp-content\/uploads\/2018\/12\/password-exposed.png?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":27803,"url":"https:\/\/mamchenkov.net\/wordpress\/2017\/07\/26\/passwords-evolved-authentication-guidance-for-the-modern-era\/","url_meta":{"origin":26717,"position":5},"title":"Passwords Evolved: Authentication Guidance for the Modern Era","author":"Leonid Mamchenkov","date":"July 26, 2017","format":false,"excerpt":"\"Passwords Evolved: Authentication Guidance for the Modern Era\" is a good collection of guidelines and concerns for password management in the modern day. Here's the bigger picture of what all this guidance from governments and tech companies alike is recognising: security is increasingly about a composition of controls which when\u2026","rel":"","context":"In &quot;All&quot;","block_context":{"text":"All","link":"https:\/\/mamchenkov.net\/wordpress\/category\/general\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/mamchenkov.net\/wordpress\/wp-content\/uploads\/2017\/07\/password-500x135.jpg?resize=350%2C200&ssl=1","width":350,"height":200},"classes":[]}],"jetpack_sharing_enabled":true,"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/mamchenkov.net\/wordpress\/wp-json\/wp\/v2\/posts\/26717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mamchenkov.net\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mamchenkov.net\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mamchenkov.net\/wordpress\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/mamchenkov.net\/wordpress\/wp-json\/wp\/v2\/comments?post=26717"}],"version-history":[{"count":0,"href":"https:\/\/mamchenkov.net\/wordpress\/wp-json\/wp\/v2\/posts\/26717\/revisions"}],"wp:attachment":[{"href":"https:\/\/mamchenkov.net\/wordpress\/wp-json\/wp\/v2\/media?parent=26717"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mamchenkov.net\/wordpress\/wp-json\/wp\/v2\/categories?post=26717"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mamchenkov.net\/wordpress\/wp-json\/wp\/v2\/tags?post=26717"},{"taxonomy":"keyring_services","embeddable":true,"href":"https:\/\/mamchenkov.net\/wordpress\/wp-json\/wp\/v2\/keyring_services?post=26717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}