ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Security mindsets of very small businesses and residential clients

    IT Discussion
    8
    45
    6.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender
      last edited by

      UG... I know your pain.

      T 1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller
        last edited by scottalanmiller

        Did you catch you own pun?

        Her password is a spelled out month.

        You called it a week password.

        T 1 Reply Last reply Reply Quote 2
        • T
          technobabble @Dashrender
          last edited by

          @Dashrender Residential clients I don't worry about so much.

          1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller
            last edited by

            Bottom line, give quick advice but don't spend your energy worrying about the lack if security if other people that are not your employees. Not your problem. Just let it go.

            T 1 Reply Last reply Reply Quote 1
            • T
              technobabble @scottalanmiller
              last edited by technobabble

              @scottalanmiller week...weak...wow, the damn spell check can't read my mind! Yeah I meant weak. And I wish I had been trying to be punny!

              1 Reply Last reply Reply Quote 0
              • T
                technobabble @scottalanmiller
                last edited by

                @scottalanmiller Good point. Now would you send the client their password in standard email because they didn't want it sent via secure email? It's my hosting server, I figure I am being security conscious by sending via secure email.

                scottalanmillerS 1 Reply Last reply Reply Quote 0
                • ?
                  A Former User
                  last edited by

                  And now you know why I stopped supporting residential client long ago.

                  They a pain in the ### and they always complain about the bill.....

                  scottalanmillerS 1 Reply Last reply Reply Quote 1
                  • scottalanmillerS
                    scottalanmiller @technobabble
                    last edited by

                    @technobabble said:

                    @scottalanmiller Good point. Now would you send the client their password in standard email because they didn't want it sent via secure email? It's my hosting server, I figure I am being security conscious by sending via secure email.

                    Absolutely. As long as they are the boss or the boss approved don't think twice, just do it. You tried to be secure and they explicitly don't want that. Time to deliver what they want.

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @A Former User
                      last edited by

                      @Aaron-Studer said:

                      And now you know why I stopped supporting residential client long ago.

                      They a pain in the ### and they always complain about the bill.....

                      Yeah. No money there.

                      1 Reply Last reply Reply Quote 0
                      • alexntgA
                        alexntg
                        last edited by

                        I know the feeling. SMBs are much like the residential clients. They know it's bad for them, but still do it anyway. If it makes you feel any better, depending on the email platform you both use, the email may be encrypted in transit anyway.

                        Enterprise clients are generally better security-wise for the most part, though do have their own headaches to deal with.

                        T 1 Reply Last reply Reply Quote 0
                        • T
                          technobabble @alexntg
                          last edited by

                          @alexntg I am using Office 365.

                          alexntgA 1 Reply Last reply Reply Quote 0
                          • alexntgA
                            alexntg @technobabble
                            last edited by

                            @technobabble said:

                            @alexntg I am using Office 365.

                            That uses opportunistic TLS. If your receiving party does the same (or forces TLS) you'll be good to go for transmission encryption.

                            JaredBuschJ 1 Reply Last reply Reply Quote 0
                            • JaredBuschJ
                              JaredBusch @alexntg
                              last edited by

                              @alexntg said:

                              @technobabble said:

                              @alexntg I am using Office 365.

                              That uses opportunistic TLS. If your receiving party does the same (or forces TLS) you'll be good to go for transmission encryption.

                              I recently had this argument with the owner of our company. He always refused to send passwords in email. Even internally. I repeatedly stated how much time he was wasting on a non-issue. Internal email is never on the public internet unencrypted for gods sake. We had an SBS server and are now Office 365. Everything is encrypted to the devices.

                              C 1 Reply Last reply Reply Quote 1
                              • T
                                technobabble
                                last edited by

                                Now I have to check my Zendesk ticketing system's encryption.

                                1 Reply Last reply Reply Quote 0
                                • C
                                  Carnival Boy @JaredBusch
                                  last edited by

                                  @JaredBusch said:

                                  I repeatedly stated how much time he was wasting on a non-issue. Internal email is never on the public internet unencrypted for gods sake.

                                  Depends on what the password is for, but other users may have been granted access to that user's e-mail. By using e-mail you may still be compromising security. It's about internal security as well as external security.

                                  JaredBuschJ scottalanmillerS 2 Replies Last reply Reply Quote 0
                                  • JaredBuschJ
                                    JaredBusch @Carnival Boy
                                    last edited by

                                    @Carnival-Boy you are taking security to the point of interfering with running a business IMO. IT is a business expense, but there is a balance to it just like any other business expense.

                                    1 Reply Last reply Reply Quote 0
                                    • C
                                      Carnival Boy
                                      last edited by

                                      Possibly. I really don't know what best practice is and to be honest, I haven't thought about it all that much. E-mailing passwords just feels wrong to me.

                                      I normally send them by SMS, which is possibly even less secure (but like I say, I haven't thought about it much until today).

                                      alexntgA scottalanmillerS 2 Replies Last reply Reply Quote 0
                                      • alexntgA
                                        alexntg @Carnival Boy
                                        last edited by

                                        @Carnival-Boy said:

                                        Possibly. I really don't know what best practice is and to be honest, I haven't thought about it all that much. E-mailing passwords just feels wrong to me.

                                        I normally send them by SMS, which is possibly even less secure (but like I say, I haven't thought about it much until today).

                                        If you know how SMS works, your pants would be brown right about now.

                                        1 Reply Last reply Reply Quote 0
                                        • C
                                          Carnival Boy
                                          last edited by

                                          Not sure. Google et al's two-factor verification is based on SMS, so how bad can it be? What's the worst that can happen?

                                          alexntgA scottalanmillerS 2 Replies Last reply Reply Quote 0
                                          • alexntgA
                                            alexntg @Carnival Boy
                                            last edited by

                                            @Carnival-Boy said:

                                            Not sure. Google et al's two-factor verification is based on SMS, so how bad can it be? What's the worst that can happen?

                                            Well, you know, their password being broadcast on-air to everyone within a few miles of your user is up there in risk. Two-factor verification isn't quite the same as a password.

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 1 / 3
                                            • First post
                                              Last post