Password Strength -...
 
Notifications
Clear all

Password Strength - Is this true?

18 Posts
14 Users
0 Reactions
6 Views
(@don-blameuser)
Posts: 1867
Topic starter
 

II am asking you, the best minds of my generation (nod to Alan Ginsberg), is this assertion about password strength correct?

Thanks,

Don

 
Posted : November 15, 2015 4:08 pm
(@edward-reading)
Posts: 559
Registered
 

You are questioning xkcd?

 
Posted : November 15, 2015 4:21 pm
Wendell
(@wendell)
Posts: 5782
Admin
 

Seems legit, especially when you consider that any character is the same from a computer's perspective. It doesn't care if it's punctuation, symbols, or whatever. It's just another character that can be just as easily guessed as anything else.

 
Posted : November 15, 2015 5:39 pm
(@jim-frame)
Posts: 7277
 

Password strength has more to do with length than selection of characters.

 
Posted : November 15, 2015 5:51 pm
 BigE
(@bige)
Posts: 2694
Registered
 

Several weeks ago (maybe more like 2 months or more ago) I read an article about this.
Don't remember where so don't ask. LinkedIn perhaps.
The article was strictly about requiring "strong" passwords and the math to back it up.
Being a former math major I can vouch for its accuracy. Simple finite math with permutations and combinations.
A simple password of 8 characters of case in-sensitive letters and numbers only can be hacked/figured out by a teenage with software they can get off the net for nothing.

That's only 36^8 permutations. 8 being the MINIMUM required length.
Now require at least one capital letter, a number, and a special character of say only 10 of them and now you are up to 78^8 possibilities. An exhaustive search of trial and error would have easily been defeated by a simple web site's check that the user hasn't tried to login a hundred times in the last second and blocks that IP right then.

That's my story and I'm sticking to it. B-)
E

 
Posted : November 15, 2015 6:09 pm
(@a-harris)
Posts: 8761
 

I am on two sites that the password has to be changed every 6mos and a password can not be repeated. They both will reject ones they deem not strong enough. I am runnin out of ideas.....

 
Posted : November 15, 2015 6:27 pm
(@paden-cash)
Posts: 11088
 

A Harris, post: 344474, member: 81 wrote: I am runnin out of ideas.....

Your age in half-year increments, multiplied by the square root of 2...and insert an alphabetical character as the decimal; carried out to how ever many places is required.

 
Posted : November 15, 2015 6:35 pm
(@jim-frame)
Posts: 7277
 

A Harris, post: 344474, member: 81 wrote: I am runnin out of ideas.

I gave up trying to remember passwords years ago in favor of a password manager. I like Password Safe, which is open source. I have over 700 passwords for various accounts, no two alike.

 
Posted : November 15, 2015 6:55 pm
(@the-pseudo-ranger)
Posts: 2369
 

Most important websites, like finacial websites, will give me about 5 incorrect tries before it locks me out. Also, they use other methods, like recognizing your computer. If it does not recognize the computer I'm on as being used before to log in, then it will ask me additional security questions.

 
Posted : November 15, 2015 8:03 pm
(@bill93)
Posts: 9834
 

The cartoon appears to come from XKCD, whose creator is quite technically knowledgeable. However, the analysis ignores dictionary attacks. Aren't they also a threat when common words are used?

 
Posted : November 15, 2015 8:57 pm
(@holy-cow)
Posts: 25292
 

It's supposed to be your mother's maiden name plus your wife's bra size plus the year you were born.

No, wait. It's your wife's maiden name plus your mother's bra size plus the year you lost your virginity.

Oops. That can't be it because computer nerds would then only have their mother's bra size to enter as the other two would be null.

 
Posted : November 16, 2015 12:19 am
(@jim-in-az)
Posts: 3361
Registered
 

I can't remember how old I am!!

 
Posted : November 16, 2015 5:43 am
(@flga-2-2-2-2-2-2-2-2)
Posts: 7403
Registered
 

" the best minds of my generation"

Although I'm in the above mentioned generation, the "best minds" attribute has long since diminished.;-)

Just use 123456 nobody will ever figure that one out.

 
Posted : November 16, 2015 6:17 am
(@holy-cow)
Posts: 25292
 

The length of the password is far more important than about anything else in order to minimize problems. Each letter has 26 permutations (plus upper/lower case) and each number only has 10. Punctuation marks are limited to what is on a standard keyboard that you would be using.

Keeping one simple so that you can remember it with no problem might help people who know you to guess at it but to a search bug it's all symbols anyway. Using "worldsgreatestdad" probably won't work anyway because someone else is already using it.

 
Posted : November 16, 2015 6:23 am
 ddsm
(@ddsm)
Posts: 2229
 

Password...Strong AND True...

GreatestSurveyorInArkansas+sasnakrAnIroyevruStsetaerG

DDSM:beer:

 
Posted : November 16, 2015 7:57 am
 vern
(@vern)
Posts: 1520
Registered
 

I disagree with the "length = strength" mindset. If you know a website requires 8 characters you have a big jump start on hacking a password. If one had a four digit password on a site, the hacker would never discover your password because they would be trying eight plus.

 
Posted : November 16, 2015 9:29 am
(@jim-frame)
Posts: 7277
 

vern, post: 344572, member: 3436 wrote: the hacker would never discover your password because they would be trying eight plus.

No hacker worth his bits would limit an automated assault to a particular password length unless he was certain it was a site requirement.

 
Posted : November 16, 2015 9:37 am
(@don-blameuser)
Posts: 1867
Topic starter
 

I' m liking the concept that a password should be true. Good point, Dan!

Don

 
Posted : November 16, 2015 8:02 pm