Thursday, August 13, 2009

A rant about password security on the NIH Commons...

This has nothing to do with photography, it is just a rant about dealing with the NIH Commons site, in particular, the measures that it takes for password security. In addition to a fairly reasonable requirements that a password include numbers and special characters, the site has an annoying and I think short-sighted policy of making passwords expire at fixed intervals. Setting the new password is a hassle because the site forbids re-use of an old password (which means they are archiving all of the passwords I have ever used there!) so it usually takes several tries to come up with something that for personal reasons is easy to remember, but satisfies all the requirements, and has been used before. And because it is a new password that I don't use anywhere else, inevitably I promptly forget it, and end up having to go through the password reset process a few weeks later. Right now NIH Commons is the only site I deal with that makes passwords expire at fixed intervals and forbids re-use of old passwords, and it is a PAIN. I think I would be much safer with a single, very long password that I can use indefinitely, than a series of passwords that I will forget unless I write them down somewhere.

Generally, I would really like to see an overhaul of the NIH Commons... It is great that it is there, but it is very 1.0, they need 2.0 features to ease navigation.

0 comments: