SWE 205 In-Class Exercise

Group, Names:
Work with your group.

This exercise is intended to get you thinking about the relation between security and usability. Think carefully here, please; the conventional wisdom about the relationship between security and usability is often wrong. Although that's slowly changing, there is a long way to go.

Think about the relationship between security and usability in the context of one-time access codes. In practice, these codes vary in length and content, with common lengths being 4, 6, and 8, and common contents being digits and alphanumeric. There are also a variety of delivery mechanisms, including email, phones, and special-purpose token generators - both hardware and software.

Consider such codes in the context of access to services in an enterprise where you might work. Be specific! You should start by narrowing down the enterprise you are considering.

What makes access codes more or less usable? Think about security broadly: what factors about codes influence risk to your enterprise? If you were setting policy for access codes in your enterprise, what would you choose and why?

Be prepared to present your analysis to the class.