The Register Home Page

back to article IT department put sticky notes on the laptops to help employees log in

PWNED Welcome back to PWNED, the weekly column where we lovingly poke fun at other organizations' security screw-ups, in hopes the rest of us can learn a valuable lesson. This week’s story involves an IT department that ought to know better putting user credentials in the precisely wrong place. Have a story about someone …

  1. Paul Herber Silver badge

    "a marketing and SEO company"

    Critical infrastructure then.

    /sarcasm

    1. Anonymous Coward
      Anonymous Coward

      If anything they were doing an exceptional job since their goal is to make everything searchable and discoverable.

      1. NoneSuch Silver badge
        Joke

        You're Laughing, But It's Coming...

        IT: We set you up on a brand new laptop. We had to reset your password.

        Worker: Great, what's the new password?

        IT: Can't tell you. It's against policy.

        1. Hazmoid

          Re: You're Laughing, But It's Coming...

          once you have worked out what your secret password is, we will need you to setup mfa using a key we will send to your email. On your new laptop.

          https://youtube.com/shorts/SOYl3omFqOw?si=D_2Ip3iR6LnltR_w

        2. Rich 11

          Re: You're Laughing, But It's Coming...

          IT: Can't tell you. It's against policy.

          Worker: Does it begin with 'p' and end with '1'?

          IT: Damn!

  2. Anonymous Coward
    Anonymous Coward

    Oh Noes

    SEO company pwned?

    Oh dear

    How sad

    Never mind.

    Couldn't happen to nicer pond slime.

    1. Aladdin Sane Silver badge
      Facepalm

      Re: Oh Noes

      Except it was a client company, not the Don Draper wannabes.

      1. BartyFartsLast Silver badge

        Re: Oh Noes

        Meh, they enable the marketing and SEO slime. Still deserved.

  3. Daniel M

    Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

    "They had a strong password policy and even made users take security training. Then they moved offices, and that's when basic security hygiene went out the window."

    I bet the users hated their "strong password policy" -- and possibly the (canned?) "security training" as well. There is no security measure so ineffective as one that everyone has been taught to hate. Finger pointing right on cue.

    1. just4this Bronze badge

      Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

      No passwords is no security.

      Passwords give better security.

      Strong password policies lead to post it notes on monitors.

      1. Excused Boots Silver badge

        Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

        It depends on your definition of a ‘strong password’. The classic Correct Horse Battery Staple is a far better password than efhiuoh^$%£, because no fucker will be able to remember the latter and will write it down somewhere. So one and only one password policy, just length, minimum 20 characters - and if they complain say use the first line of your favourite book, etc.*

        Obligatory xkcd link

        * yes I know a person’s favourite book could be gleaned from social media posts, and first line/sentence could be inferred, but better than most other methods. Also do not use ‘In the beginning God created the Heaven and the Earth’, because although that may well be someone's favourite book; but it’s a bit obvious. See social media posts. I don’t know what the first line of the Torah or the Quran are, but similar would apply.

        1. PRR Silver badge

          Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

          > what the first line of the Torah {is}

          Same as the Jewish and Christian bible.

          1. Anonymous Coward
            Anonymous Coward

            Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

            Only in a mirror.

        2. Anonymous Coward
          Anonymous Coward

          Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

          The oblig XKCD is interesting, but given contemporary tech...it's a bit dated. A password made out of 4 random words would take about 32 minutes to crack with current tech (assumptions being the password isn't salted, or the salt is known). There are 171,000 actively used words according to the Oxford English, which seems like a fair number and prevents us breaking our own "ease of memorability" theory by introducing overtly purple prose into our passwords. E.g. Dave in the warehouse isn't going to remember "Sufficiently Succinct Perfunctory Pangolin"...100% hes fat fingering that one...so a reasonable subset is...reasonable. Based on that, we get eight hundred and fifty-two trillion permutations (if we go with 4 words)...you'll have to forgive me if my maths starts getting a bit "rounded", the numbers here are insane and I'm running out of paper...an RTX 4090 can do around 25GH/s (which is 25 billion a second), which means you can churn through 825 trillion hashes in approx 32 minutes.

          The reality is, the word pool would be much smaller and therefore the permutations significantly fewer, since we need to ensure that all the words in the pool are simple and not flowery.

          For bruteforcing, it doesn't actually matter the format of your password, only the character length matters, because whether your password is hard or easy to remember is irrelevant for a bruteforcing algorithm. All passwords are the same...only the length matters.

          Memorable passwords only benefit the user, a long random password is fucking annoying for the user, because they will forget it, but it does lead to a side effect that also strengthens passwords...and that is rotation...you as a sysadmin will have to reset it so often that you won't have to worry about breaches and data leaks as much. Double edged innit?

          1. IGotOut Silver badge

            Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

            @A/C

            So your billions of calculations a minute are...well useless if you have a lockout policy of say 5 to 10 attempts.

            Conflating stolen credentials and login passwords on a post-it note are completely different things.

          2. theDeathOfRats

            Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

            There are 171,000 actively used words according to the Oxford English

            Now try that with some other languages. English is just but one.

          3. The Organ Grinder's Monkey Bronze badge

            Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

            Ref XKCD link,

            Non-techy Luser here, sorry.

            I've always been puzzled by the way that the "Horse Battery Staple" thing splits the words which feels to me like turning a 30-something character problem into several much smaller (& therefore more easily solved) problems. Presumably the answer is "hashes"? & I should just nod, smile sweetly and accept what those who understand such things tell me, & not cling onto my Bletchley Park-vintage concepts of code-breaking?

        3. Paul Herber Silver badge

          Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

          You have an extraneous " in your xkcd URL

        4. Anonymous IV
          Unhappy

          Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

          Using first line of book as pass phrase.

          I can only remember the first lines of two books:

          "Omnia Gallia divisa est in partes tres."

          and

          "It was a dark and stormy night..."

          Which should I use?

          1. Tom Chiverton 1

            Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

            1tWasAdark&st0rmyn8

            1. Anonymous Coward
              Anonymous Coward

              Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

              Dark and stormy Nate?

          2. nobody who matters Silver badge

            Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

            A long time ago, in a land far, far away.....

          3. Bebu sa Ware Silver badge
            Coat

            Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

            > "Omnia Gallia divisa est in partes tres" and "It was a dark and stormy night..."

            > Which should I use?

            Omnia was a Gallia dark in partes stormy tres – would be favourite.

            Omnia was also the theocratic state founded by worshippers of Om on the Discworld continent of Klatch. The Omnian Quisition if not universally unexpected was feared.

            † "Gallia est omnis divisa in partes tres"

          4. Anonymous Coward
            Anonymous Coward

            Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

            Mixing languages is also good, if you know words in a few.

      2. Anonymous Coward
        Anonymous Coward

        Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

        ...and Post it notes lead to the Dark Side.

        1. The Oncoming Scorn Silver badge
          Pint

          Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

          where they have cookies. :D

      3. Tim99 Silver badge
        Big Brother

        Re: Providing Negative Incentives and then Clutching Pearls: However could this have been avoided ?

        That was certainly true. I was responsible for a number of earlier Novell Netware networks. Novell were based in Utah, and seemed partial to religious themes, like being forced to change user passwords after 40 days. Post-it notes had become a thing, and most of the systems that I saw had a few on screen bezels with passwords, and occasionally the account name as well. I "counselled" the relevant users and managers. It worked - No Post-its on bezels. I pretended that I didn't know that they were now under their keyboards.

  4. PenfoldUK

    My memory may be at fault here, but at one place I worked a while back, the new laptops did have sticky notes with employee name on them. But only enough info to turn them on first time. You then had to choose a Bitlocker PIN.

    Even then, you couldn't log into the network without separately provided credentials.

  5. Dr Dan Holdsworth
    Boffin

    The general policy should, if you want the security to be reasonably tight, be a secret and a token of some description that together get you into the account.

    So, username, password and 2fa token system like a dongle or a mobile phone (provided that the mobile phone has some sort of security on it too).

    A fingerprint isn't enough. The Sci-Fi author Michael Marshall Smith, in one of his stories details why. The protagonist is a small-time criminal engaged in a less than legal but highly lucrative trade. One morning this trade goes sideways and he is forced to request a loan from a colleague. Said colleague cannot provide said loan so offers an alternative. This consists of a finger attached to a small life support device, said finger giving access to the bank account of its former owner (who was deprived of his life around the time he was deprived of his finger). The lesson is simple: fingerprints can be stolen, secrets are more difficult to steal.

    1. Yet Another Anonymous coward Silver badge

      So a shelf of new laptops with biometrics and a finger taped to each of them?

      1. KittenHuffer Silver badge

        You know the BOfH sooooo well!

      2. frankvw Silver badge

        "So a shelf of new laptops with biometrics and a finger taped to each of them?"

        Tempting... but no. Consumer-grade fingerprint scanners, and even fingerprint scanners that claim to be better than consumer grade, are notoriously easy to fool. They are designed as bolt-on module, designed to be made as small and cheap as possible rather than as secure as possible. See the Mythbusters episode from 2006 for a demo; things have not improved much since then.

        What I don't get is why equally inexpensive webcams aren't used more often for biometric security. Computing power and software have evolved more than sufficiently for this. I live in South Africa where technology is hardly cutting-edge, but one of the local banks requires a selfie with a smartphone prior to certain transactions to verify the account holder's identity. Even on the most inexpensive devices this works well: the data is obviously sent to a back-end server, not processed on the device, so all you need is a camera that's good enough to determine the position of eyes, ears and other biometric features. So pretty much any laptop built in the past 20 years can do that. And even desktops have webcams these days more often than not, what with Zoom, Meet and Teams having become a staple of the modern office. Biometric security should have been as pervasive by now as well. But no.

        1. The Organ Grinder's Monkey Bronze badge

          What steps does your SA bank take to prevent this system from being fooled by a photograph. I assume that this is also the unstated objection of your downvoter (which wasn't me, ftr.)

          1. Mark Ruit

            I don't know what the SA bank system uses, bur every time I have used my camera as a 'log-in' or self-identifying device, part of the schtick has been an instruction to "Smile", or to "Turn your head" ("Left" or "Right" also being specified in that case).

            Incidentally, 'gurning' works just as well - any physical displacement of features can indicate 'not-photograph' - but gurning somehow seems much more satisfying, at least to me.)

  6. Anonymous Coward
    Anonymous Coward

    Don't need postits

    At Uni, late 70s, user accounts were of the form AAAAnnnn, and each year a new set was generated for the roughly-expected student intake. Passwords formed a similar sequential pattern. If we knew that the year's intake was 160 students, we could guess that 200 accounts were pre-generated, so by starting at the far end we had ~40 accounts with easily guessable usernames & passwords which would never be allocated. Since each had storage & CPU quotas this was a very handy way to get access to more resources, we just had to divvy-up the accounts between those in the know, and change the passwords.

  7. Anonymous Coward
    Anonymous Coward

    Initial Accountname/Charge #/Password Transfer

    ... send the credentials through an encrypted channel ...

    At my uni, you had to physically show up at the computer accounts department and show your photo ID. They then gave you a punched card, printed with the relevent info.

    1. Anonymous Coward
      Anonymous Coward

      Re: Initial Accountname/Charge #/Password Transfer

      Punched card - also encrypted?*

      * i.e. punched in EBCDIC

      1. KittenHuffer Silver badge

        Re: Initial Accountname/Charge #/Password Transfer

        And must be entered on a Dvorak keyboard!

        1. Excused Boots Silver badge

          Re: Initial Accountname/Charge #/Password Transfer

          "And must be entered on a Dvorak keyboard!”

          You are a BOFH and I claim my $£5

          1. Anonymous Coward
            Anonymous Coward

            Re: Initial Accountname/Charge #/Password Transfer

            What's a dollar pound?

      2. Anonymous Coward
        Anonymous Coward

        Re: Initial Accountname/Charge #/Password Transfer

        Were I worked a long time ago. The someone wrote a program for the mainframe that let people do a kind of Usenet communication.

        There was much discussion about it's security as it required a sign in with a password. The writers claimed the passwords were encrypted.

        Well I knew how to see which files you used when running a program. So I eventually looked up which file was used. Then I made a copy of the file and then I changed my password.

        Looking at the two files I found my user-id record (I have a unique name). I couldn't read either password at first. But they didn't seem to be totally random when I changed my password several times. But then I remembered that the nice raw file viewing program I was using let you view the file in several different encodings, like binary, octal, ASCII... and EBCDIC. Yes, the "encryption" was to store the passwords in EBCDIC. These were not IBM mainframes so better than nothing, but not much better.

      3. Anonymous Coward
        Anonymous Coward

        Re: Initial Accountname/Charge #/Password Transfer

        They didn't bother encrypting the punched card.

        Serious computer science students back then could (laboriously) read the BCD hole-punches directly.

  8. Steve Hersey

    It's even worse than that...

    With a pile of laptops stored insecurely, it would be trivial for someone to lift two or three, and they even have valid login credentials for them!

    The secure way to handle this would be to have the staffers individually come to IT, show ID, collect their laptop, and enter their new password on the spot, so IT can verify they've done it without needoing to know the new password.

    Yes, this is tedious, but not as tedious as a data breach.

    1. Excused Boots Silver badge

      Re: It's even worse than that...

      "Yes, this is tedious, but not as tedious as a data breach.”

      True but try convincing senior management of this fact!

      1. Anonymous Coward
        Anonymous Coward

        Re: It's even worse than that...

        To be fair, it's not them you have to convince, it's me. Some guy claiming to be my boss turned up 3 times today with what I think is a fake passport. He definitely looked like my boss, threatened me like my boss...but his passport looked a bit clean, so I told him to fuck off and had security kick him out of the building.

        I got summoned to my bosses office to ask why I had him thrown out and had all his credentials revoked...I wasn't falling for that, so I asked for his passport again...it was only the same fucking one, so I had him thrown out again.

        The "Papier Bitte" protocol has never failed me.

  9. JWLong Silver badge

    Security..........

    Yes, we've heard of it!...................

    /s

  10. Anonymous Coward
    Anonymous Coward

    IT department put sticky notes on the laptops to help employees log in.

    Lol this is so stupid I don't know where to begin. I put another post it over the top to cover the credentials. For those of you that don't have the kingly budget I have, you can simply fold one post it note in half...just remember to write the password on the inside after you fold it.

    We had a junior once who wrote the passwords on before folding and sometimes it would be on the outside. Oh how we lol'd. The good old days.

    1. Excused Boots Silver badge
      Trollface

      Re: IT department put sticky notes on the laptops to help employees log in.

      "For those of you that don't have the kingly budget I have, you can simply fold one post it note in half...just remember to write the password on the inside after you fold it.”

      Ha amateurs!

  11. Anonymous Coward
    Anonymous Coward

    Healthcare…

    In my hospital, the security is high because the sticky label, is *under* the keyboard.

    Sometimes with additional security.There may be 2 or 3 old labels to obfuscate the real one…

    Oh, and all the door access codes for the wards are written clearly above, but in high risk areas, it’s down the side of the wooden door frame.

    1. Anonymous Coward
      Anonymous Coward

      Re: Healthcare…

      "it’s down the side of the wooden door frame"

      You shouldn't take the piss man, they do this in neck injury units to prevent the patients escaping.

    2. Anonymous Coward
      Anonymous Coward

      Re: Healthcare…

      Similar with a major UK airport, the door to the airside crew areas was in a public area but was secured with a six digit code

      It had been carefully scratched into the plaster next to the keypad in a public area.

      Obviously when it was spotted and reported by security facilities painted over it.

      Leaving the impression of the code still visible but nicely painted.

      1. G.Y.

        NSA Re: Healthcare…

        I bought something at the NSA (since!) museum. Receipt showed the credit-card; when I mentioned it, they crossed it out with a pen

  12. JackHarveyCan

    Pro Tip:

    Hide the password by taping it underneath your keyboard or mouse connected to your docking station, place the sticky note into your wallet, or write it on the back of your boss’s business card in said wallet, or even write it on the piece of tape placed over your camera, then cover that with a decoy piece of tape. Genius. Follow me for more super secure security tips.

  13. JackHarveyCan

    IT Asset Disposition

    I’d like to add that as someone who has handled tens of thousands of laptops, desktops, and related accessories, there are a concerning number of major corporations that still engage in this practice, especially taping to the monitor.

    1. blu3b3rry Silver badge

      Re: IT Asset Disposition

      I have an elderly Core2Duo laptop sat next to my desk at home. On the underside is an asset number label that also has a username and password.

      By the time the machine arrived in my possession the hard drive had long since been removed, so no idea what it did.

  14. ColinPa

    Our algorithm is so strong - we need to write down the password

    I remember working with one of the test team, and as I was talking to him - he gave me "the Paddington stare". He said he was working out the password

    You take the 3 letters of the month, move them forward by 3 letters, so Jan -> KBO, take the year and add 1 so 2026 becomes 2027 and put a ! or a ? depending on the parity of the month.

    Wow I said - no wonder you were giving me the stare as you worked it out. No he said, I was looking past your right ear at the white board, where is is written down - it is the middle 8 characters of the 10 character string at the top, and I didnt have the right glasses on.

    1. Anonymous Coward
      Anonymous Coward

      Re: Our algorithm is so strong - we need to write down the password

      "Jan" moved ahead by 3 letters isn't KBO. That's 3 letters each moved ahead by 1.

  15. Confucious2
    IT Angle

    Post it

    Many years ago my wife worked at a company and every time IT wanted to install an update, they would send out an email asking everyone to leave a post it note with their username and password on their computer so they could install the update…

    I’m sure they don’t still do that.

    1. Sam not the Viking Silver badge

      Re: Post it

      You say "Many years ago" but I can assure you that not that long ago, we were asked to do exactly that whilst the system was 'upgraded'. When I eventually regained control of my laptop, security was so tight that I was unable to open any file at all, never mind run a suite of programs necessary to perform my set tasks. The new company handling our systems couldn't believe that anything other than 'Office' might be required. "What do you need a data-acquisition system for?"

      My customer, his consultant, the end-user and their associated entourage, visiting to inspect the (very expensive) machine operating as the specification demanded, witnessed the slow restoration of my hitherto esteemed status.

    2. Little Mouse

      Re: Post it

      My wife still works at a company where IT expect her to hand her laptop over now and then along with her password, so that they can log in as her to install updates.

      I told her that was F'ing nuts and no company on the planet has done anything remotely like that since at least 2002, and anyway there's no excuse for any IT dept anywhere to ask for your password.

      Their reply?

      "If your husband works in IT, then he'll know about User Profiles"

    3. Bebu sa Ware Silver badge
      IT Angle

      Re: Post it

      The adduser shell script at one place, actually emailed to the manager the added user's name username, cleartext password etc so he could send the password to any user who had forgotten his/her password. The new user entered the new password at the script's prompt in the manager's office when the account was being set up which as ok up to that point.

      The script captured the password in a shell variable and used it on the command line (ie ps visible) to separately set the Unix and Windows passwords.

      IT departments aren't typically staffed by sharpest tools nor the most consistent. Imagination definitely isn't top of the list of mandatory requirements.

      (What tripped me up on my first day was that the script truncated my proffered password at the first white space [IFS]. )

  16. Anonymous Coward
    Anonymous Coward

    Saw something similar a few years back. Rather ironically, the username/password couldn't be used on some of the laptops they were set on, because these were refurbished laptops (the company didn't want to purchase new ones) and a number of them had faulty keyboards!

  17. steviebuk Silver badge

    Sometimes

    This does annoy me "Even the IT department should not know your password, should someone in IT themselves turn rogue.". Making it 1000s times harder to support people with that. Yes, I understand but when you get some fuckwhit who's incapable of using their fucking fat fingers to type their login details into the fucking MFD to register their card, I end up just doing it myself so I can move on to the next ticket. So yes, sometimes, I do have to get them to give me their details.

    Had one person insist "I'm doing it right, I'm doing anything wrong, the MFD just isn't working". OK, let me try, working with my details. Let me watch you "See, its not working, its not letting me in". OK, well way to test it is if you give me your login and I'll try. So I do. Doesn't work. I try to login to Windows with same details, doesn't work "This password is def wrong then".... "No it isn't" she bleets. "Look....oh...erm, there maybe a . at the end".

    Oh look, now the fucking printer works.

    Cunt!

    1. Anonymous Coward
      Anonymous Coward

      Re: Sometimes

      IT doesn't need to know a user's pw. They may need root or the ability change a user's pw.

      1. steviebuk Silver badge

        Re: Sometimes

        Yes but then you can never prove "No, nothing was wrong with the MFD, you were just putting your password in". Sick of users blaming their fuck ups on IT so sometimes, you want to gently, without being an arse, show them without words that "You were putting your password in wrong".

  18. xyz123 Silver badge

    for over 4 years a certain fruity phone maker had an EXTERNALLY ACCESSIBLE HR System.

    Username was a type of fruit the company was named after

    Password was the same fruit

    This was a system showing employee names, addresses, job titles, contact details and whilst bank account were redacted to asterisks, it had the ability to "update" them with NEW bank details.

    There was a rumor someone VERY famous at the company had their details changed, didn't notice for 2 months and the company glossed over it for reputation, paid the employee what they were due and never went after the thief. Because suing them would have exposed how incompetent they were behind the scenes and cost them a lot more

    1. Bebu sa Ware Silver badge
      Happy

      fruit the company was named after

      Orange ?

      Just kidding. I think more scrumpy than OJ.

  19. Blackjack Silver badge

    Wow, that's worse that writing the password on the back of business cards.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon