The biggest vulnerability in most enterprise networks is the authentication system -- especially if it relies solely on passwords. Protecting a computer network using employee-created passwords is like protecting a jewelry store on a busy street with one small lock -- and hiding the key underneath the doormat. Although there are glaring weaknesses in this nearly ubiquitous authentication method, passwords are "a necessary evil," Yankee Group security analyst Eric Ogren told NewsFactor. Fortunately, several additional methods, used in conjunction with passwords, can boost system security to a significant degree. Which weapons in the authentication arsenal should an IT administrator use -- and when is a network is secure enough?
Although passwords are widely used, they are far from sufficient for ensuring a high level of security. Even a modestly skilled hacker Latest News about hacker, armed with a mid-level hacking program, can break into many password-protected networks without breaking a sweat. The real culprits are employees, Ogren said, because they unknowingly cooperate with hackers by choosing passwords that are easy to crack. Passwords containing only four characters are particularly vulnerable.