Prince William photos accidentally reveal RAF password
nakedsecurity.sophos.com
nakedsecurity.sophos.com
I've got some better advice. Don't stick passwords to the wall (or monitor) in the first place!
http://people.csail.mit.edu/torralba/publications/shadows.pd...
The username and password, then, keep out people who don't have access to that room.
Milflip's an Internet-based web site for military flight information, primarily approach processes for different places. If it's the same milflip it won't be too serious. The user guide is publicly available online[1], as is the site.
Purely as an FYI, what Americans would refer to as a court-martial would also be a court-martial in the UK.
You'd think, at least, that it could be in a binder hanging on the wall.
Edit: Whoever downvoted me obviously undermines how quickly 'password lag' builds up if you're made to change your passwords often and forced to not use the last 3 or 5 passwords again.
And if you are nontechnical that means paper. I consulted a decade ago with a team that had ~5 systems like this. The office was awash in sticky notes. Sometimes security policies are a menace to actual security.
Whoever printed that out will probably be fired pretty much straight away.
Two factor auth is really the best way, and although it's kludgy, it provides the best protection. And it includes a password.
some open source projects have better security, it seems, than the MOD. wtf? talk about an asymmetric world.
given the nature of the work the system shouldn't be comprisable if a picture of a password gets out, which is suggested in this case. (the fact that it was written down suggests other failings, yes, in all sorts of areas.) your objections (cost, usability, etc), in this case, are pretty weak when you consider the sensitivity of the assets being protected.
soft token-based two factor auth is a growing commodity. key-based auth is commonplace now, and is recognized as strong. finally USB-tokens are also COTS at this point. given that a major government agency which supposedly knows a lot about security got hosed by this, i would expect the market to lag, not lead, security practices.
Example: http://arstechnica.com/security/2012/09/windows-passwords-ex...
while my job in infosec isn't related to AAA i know that better stuff exists and that it's in budget and applicable here. i offered some ideas, you offer up criticisms, but i'm still wondering how no one had spoken up about the crappiness of it being 2012 and we still rely on passwords.
just a few days ago this link was posted here:
http://kod.ozgurcakmak.com.tr/passwords-do-we-really-need-to...
and also this one from wired:
http://www.wired.com/gadgetlab/2012/11/ff-mat-honan-password...
given all the breaches in the past 2 years by lulzsec and relatives you'd expect a bigger outcry here. nope, not yet.
you honestly think this is the best we have? i sure don't.
here's some (i imagine) better COTS stuff out there: http://www.yubico.com/products/yubikey-hardware/yubikey/
Some implementations are, but the concept is sound and can work smoothly. Your second factor could be a smart card or a USB dongle that's simply plugged in. Like an ATM, especially European ones.
One of the big problems with automated online systems is that the user often has no chance to notice that something is going wrong. Giving them a chance to notice anomalies improves security.
E.g. I'll know if my house is broken in to, unless it's done by the very best (funded). OTOH someone could be copying my harddrive as we speak, and in many cases I'd have no idea.