|
Posted by Brian Komar [MVP] on October 3, 2006, 12:07 am
Please log in for more thread options I have to go with Lanwench on this one. Complexity is good. Keep it in a safe.
Break glass in
case of emergency
Brian
> So is it better practice to have it expire, or to never expire?
>
>
> >> Are there any risks associated with an expired built-in Administrator
> >> password? I've been googling but can't seem to quite get results that
> >> speak
> >> to this issue.
> >>
> >>
> >>
> > The risk is that you cannot log in with the account once the password has
> > expired without
> > resetting it. If an attacker is able to determine the original password,
> > due to poor password
> > implementation, they could change the password from under you.
> > Brian
>
>
>
|