Re: Strong Passwords Revisited

From: Jeff Williams (frostback1963@yahoo.com)
Date: 01/21/03


From: "Jeff Williams" <frostback1963@yahoo.com>
Date: Tue, 21 Jan 2003 15:49:00 -0600


...snip...

Very interesting posting. Good job.

One problem with "strong" passwords is that they're very hard to remember.
"zucchini" is easy to remember. "*&cFho4#" is, for most people I know, hard
to remember. What are such people likely to do with hard passwords?
They're going to write them down (and often post them on a yellow sticky on
their freakin' monitor). This is not very good from a security perspective.

I've often wondered why passwords seem to be limited to 8 or 10 characters.
Why not limit them to, say, 32 or 64 characters and let people use phrases
that they can easily remember? Many people have a vast repository of
remembered pop songs. Others memorize scripture or poetry. Such phrases do
serious damage to the concept of dictionary attacks as well as to BFI
attacks.



Relevant Pages

  • Re: US Military bans HTML in emails
    ... Complex passwords are not that much harder to ... Consider a password with a choice of X different characters for each ... takes using all upper- and lowercase letters, ... I can see only two advantages of complex passwords: ...
    (comp.os.vms)
  • RE: Basic question
    ... If somebody else hasn't covered it already, I'll try to send out a Kerberos ... > Unicode character set and can be up to 128 characters long, ... > Pre-W2K user interfaces limits do not allow passwords to ... I believe that you are referring to *LM* hashes. ...
    (Focus-Microsoft)
  • Re: Paper & pencil password algorithm
    ... generator and generate a password as a permutation of a whole ... The advantage of a random sequence generator is that I can make my ... I can't imagine ever wanting passwords ... convenience I'll probably keep most of them between 20 and 50 characters ...
    (sci.crypt)
  • RE: Password statistics and standards
    ... If you shut off the storage of LM hashes, over 9 Characters will buy you ... Take a look at Perfect Passwords for some creative ideas: ... information about accounts which is helpful in telling me ... Norwich University ...
    (Security-Basics)
  • Re: US Military bans HTML in emails
    ... You mean like requiring 6-character passwords to now be "complex"? ... the need for non-alpha characters. ... I've seen passwords with zeros for O's and 3's for E's. ... What hacker ever think of that? ...
    (comp.os.vms)