Solomonster

Back in 10.

Wednesday, October 25, 2006

 
Save The Cheerleader, Save The World

Monday, October 23, 2006

 

The Great Debates: Pass Phrases vs. Passwords. Part 2 of 3 - Technet Column

The Great Debates: Pass Phrases vs. Passwords.

Following up on my previous post pointing you to good pwds, this is actually a decent enough "debate" on passwords vs. passphrases. the author throws around some pretty useless numbers early on, but quickly gets to the point that I thought was worthy of your attention: Passwords are often made harder to crack by adding "complexity" to them, e.g. a-z and A-Z and 0-9 and a bunch of other random characters, all mixed together. But, the way most people would implement a pass phrase is going to be all words and maybe some punctuation. Those words, as individual symbols, may be quite easy to crack, as opposed to viewing them as 30 separate symbols to brute-force your way through.

Time for an example, right?

Here is a 9-digit password:
!k1eV3r?+

And here is a 34-character passphrase:
The Force is strong with this one.

If the cracking program assumed that passwords longer than, let's say, 15 characters are likely to be sets of English words rather than a randomish password, then it could look at that pass phrase as 7 complex symbols rather than 34, and cut down the hacking time by millenia.

That's a real world mark against deciding that pass phrases are better than reasonably well-constructed passwords, isn't it? (No, I don't want to qualify my subjective opinion of what is "reasonably well-constructed", but thank you for the offer, all the same.)

 

Password size does matter

Choose a better password without complicated formulas and mnemonics.

Password size does matter | InfoWorld | Column | 2006-07-21 | By Roger A. Grimes

Archives

May 2004   June 2004   August 2004   September 2004   October 2004   November 2004   January 2005   March 2005   April 2005   May 2005   June 2005   July 2005   September 2005   October 2005   November 2005   December 2005   January 2006   February 2006   March 2006   April 2006   May 2006   June 2006   July 2006   August 2006   September 2006   October 2006   November 2006   December 2006   January 2007   March 2007   June 2007   July 2007   August 2007   September 2007   October 2007   February 2008   March 2008   April 2008   May 2008   June 2008   July 2008   August 2008   September 2008   October 2008   December 2008   January 2009  

This page is powered by Blogger. Isn't yours?

Subscribe to Posts [Atom]