Solved

Security Concern: Usernames in Email Addressed

Posted on 2007-03-28
2
250 Views
Last Modified: 2011-09-20
Our organization currently assigns email accounts for our staff using their username…

Example: If the username is smith123, then their email address is smith123@ourcompany.com

When we consider security, we now realize this isn’t the preferred method of assigning email accounts. Now the decision/question is do we…

A) Reassign email accounts, change all the business cards, contact everyone that has our emails addresses on record and hope they update their records… OR

B) Change the usernames, make changes in all the programs the reference these usernames in hardcode, watch for any anomalies and hope nothing is failing ‘under the hood.’

Another option/question is how vulnerable are we to leave things the way they are? If passwords consist of eight complex characters (a-z,A-Z,0-9, !-$), would bumping this up to 10 charters be the ‘easy’ solution?
0
Comment
Question by:todjklki
2 Comments
 
LVL 27

Accepted Solution

by:
Tolomir earned 63 total points
ID: 18809649
I would simply start with additional official email addresses.

like firstname_surname@company.com (or j.sixpack@company.com)

The now active email addresses could be kept, just when it's time to make new business cards use the new email address. Also change the signatures in your emails to match the new email-addresses.

After a year or two the "old" email addresses will be forgotten by your business partners, within company you can use them as long as you wish.

Tolomir
0
 
LVL 32

Assisted Solution

by:r-k
r-k earned 62 total points
ID: 18812288
Good advice from Tolomir. I just want to add that IMO a 10-char password is always much much better than an 8-char password. In fact length of the password is much more important than the complexity, so long as single dictionary words and common names are avoided.

Whether you should change the email addresses right-away or use Tolomir's suggestion depends on your particular security requirement. In a highly secure environment, probably yes, but other steps such as firewall, lock-outs, password length etc. are surely more important than hiding usernames.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

You cannot be 100% sure that you can protect your organization against crypto ransomware but you can lower down the risk and impact of the infection.
Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

863 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now