Your passwords don’t suck, it’s your policies
Results 1 to 7 of 7

Thread: Your passwords don’t suck, it’s your policies

  1. #1
    Join Date
    Apr 2000
    Location
    Sheboygan, WI
    Posts
    53,391

    Your passwords don’t suck, it’s your policies

    Your passwords don’t suck, it’s your policies

    Interesting take.
    http://www.zdnet.com/blog/identity/y...selector-blogs

  2. #2
    Join Date
    Feb 2000
    Location
    Idaho Falls, Idaho, USA
    Posts
    18,428
    Excellent article. Password policies often DO cause problems.

    Some policies are so strict that only completely random character sequences will be allowed. The trouble with those is that no one can remember them, so they end up being written down and/or stored in insecure locations.

    While a minimum length is needed to prevent brute force cracking from being successful in a reasonable amount of time, longer passwords are not necessarily more secure if other methods can be used to guess them.

  3. #3
    HAN's Avatar
    HAN is offline Virtual PC Specialist!!!
    Join Date
    Feb 2002
    Location
    USA
    Posts
    4,319
    Interesting read.

    The question I have is that they claim to be able to recognize patterns. And thus, passwords with patterns are weaker.

    I have read claims (on Steve Gibson's grc.com site) that length of a password, with or without a pattern is what matters most (note I didn't say all but most.) This is due to the assertion that the password is not discovered by one or a few characters at a time (like on TV or in the movies) but must be discovered in its entirety.

    I am no cryptologist but I don't see how Passfault sees any patterns in lengthy passwords. Certainly the "test" on their webpage is no proof. They are seeing the phrase you type (they are NOT cracking the password in that amount of time!)

    I would like to see discussion between some experts on these differing points of view!
    Last edited by HAN; May 16th, 2012 at 07:22 PM.

  4. #4
    Join Date
    Apr 2000
    Location
    Sheboygan, WI
    Posts
    53,391
    Like i stated, interesting take!

  5. #5
    Join Date
    May 2012
    Location
    London
    Posts
    10
    Really interesting article, will make me think about how secure my passwords really are.

  6. #6
    HAN's Avatar
    HAN is offline Virtual PC Specialist!!!
    Join Date
    Feb 2002
    Location
    USA
    Posts
    4,319
    Well, there has been more discussion of this around the web. As I suspected, the PassFault "method" has some serious issues. I place no confidence at all in their theories OR their tool.

    This link sums it up very well... http://itknowledgeexchange.techtarge...-length-redux/

  7. #7
    Join Date
    Apr 2000
    Location
    Sheboygan, WI
    Posts
    53,391
    Nice, glad to see someone did that.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •