[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference decwet::windows-nt

Title:Windows NT
Notice:See note 15.0 for HCL location
Moderator:TARKIN::LIN.com::FOLEY
Created:Thu Oct 31 1991
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:6086
Total number of notes:31449

5718.0. "Naming an alternative Adminsitrator account" by ACISS2::DATZMAN (Vee Vont To Pomp You Up) Wed Feb 19 1997 09:54

    One of the recommended approached to improving NT account security is
    to disable the default Administrator account and create another account
    with the same priviliges to perform daily admin tasks.
    
    The question I have is around the name for the new account.  Has
    anybody taken this approach and what kind of names are you using?  Does
    Digital do this internally ?  It is suggested that the name be fairly
    long and not easily guessed - so changing the account form
    Administrator to manager or root or system would not suffice.
    
    Any ideas?
    
    Thanks,
    
    Dick
    
T.RTitleUserPersonal
Name
DateLines
5718.1BIGUN::nessus.cao.dec.com::MayneWake up, time to dieWed Feb 19 1997 13:224
If you have a "standard" alternative account, what's the point of doing it in 
the first place?

PJDM
5718.2BHAJEE::JAERVINENOra, the Old Rural AmateurWed Feb 19 1997 14:0818
    re .1: Doesn't parse...
    
    There's no 'standard' alternative account... I thought .0 was asking
    for recomendations how to do one. Though I haven't seen any
    recomendations either...
    
    >It is suggested that the name be fairly
    >long and not easily guessed
    
    So how about "Vee Vont To Pomp You Up" as the Administrator account?
    ;-) Oh well, it's just a bit too long (20 is the maximum).
    
    Really, if you're really paranoid, just take something that's not
    commonly used on any system for the sys$mangler, and not related in any
    way to the real administrator(s). Might sprinkle in the odd Umlaut etc.
    (how would you line 'j�rjestelm�nvalvoja' - I believe that's
    administrator in Finnish  :-)
    
5718.3Try $qz149bob !!PGREEN::SACKMANJPedalo'ing the InternetMon Mar 10 1997 00:2111
    From a security viewpoint I have always suggested names that are very
    innocent looking or very complex.
    Try a username like Sue_James (who does not exist), no description
    (remember that users can access the User Manager initial screen) or a
    user type description ( Sue James - temp ), and a password including
    shift characters.
    An old username of mine from the '70s was $QZ149BOB !! Remember that no
    matter how complicated a username is to type in initially, it gets much
    easier with a couple of hundred logons!!!
    
    	Jon.