Password Security

Passwords are such a touchy subject. We know you find them annoying, PCI "stuff" annoying and us (the messenger) responsible for all this aggravation. This part to me is really common sense. Restrict users to only the access they require to perform their duties and use strong, un-guessable, invulnerable to dictionary attacks (avoid whole words, especially phonic words) and unique.

PCI/DSS wants you to remember a password at least 8 characters long constructed of upper & lowercase letters, numbers and include special characters too? Plus they want you to change it at least every 90 days? AND you need to log these changes for each user?

I know it sucks, it's hard and you don't want to do it. Neither do we, but it is not only part of your responsibility as an ecommerce merchant, but a responsibility to your customers to protect them, their credit cards and personal information.

Security standards require that your passwords associated with ANY part of your website be a minimum of 8 characters in length, include upper and lowercase letters, at least 1 number and and should include special characters as well. This tool should help you create multiple, unique passwords for your websites, gateways, administration sections, email etc so that you can change your passwords more quickly every 90 days... remember to log each user's most recent password change.

