Forum Home
Press F1
 
Thread ID: 125239 2012-06-16 04:42:00 Fresh look at password strength linw (53) Press F1
Post ID Timestamp Content User
1281984 2012-06-16 04:42:00 Found this article thought provoking:- ask-leo.com

Seems as if size is important:D
linw (53)
1281985 2012-06-16 05:25:00 Yes, one page of text as a password should do it. pctek (84)
1281986 2012-06-16 08:49:00 I have multiple passwords that I use and cycle around and retire as I feel necessary.

I think the next set of passwords I come up with will be something along these lines. I've run into this before though, I tried using a looong passphrase and the system wouldn't let me, hah.
That said systems seem to be acknowledging the necessity of it now.

"Applejack is indeed the silliest and best of all ponies".
8ftmetalhaed (14526)
1281987 2012-06-16 09:19:00 Yes, one page of text as a password should do it.
For a weaker password maybe :D
Nick G (16709)
1281988 2012-06-18 21:03:00 I was really impressed with Lastpass most of my passwords are now 16 character long, randomly generated mix of upper and lower and special characters..

www.lastpass.com
adslgeek (14687)
1281989 2012-06-19 00:48:00 That should keep the cracker going for long enough!!

The interesting thing, though, is that you can use a memorable one so long as it throws in a couple of char sets (capital, lr case, spec char) as long as the password is a reasonable size. Like ".......Password......" is still an extremely strong one.
linw (53)
1281990 2012-06-19 01:52:00 Its BS, the real world is a bit different
I worked in a company that enforced a pretty strict password policy
No names, must be 8+ characters, must have numbers etc in it, changes every 6 weeks, new password must be completely different to the old pass.

So what actually happened was the passwords became to complex & changed too often for staff to remember
So.. some guys were constantly ringing IT to have the pass changed because they forgot it
But most simply wrote down the ever changing password on a bit of paper near the monitor
So much for password security then.. :badpc:

All you really need is to break up the password with 2+ numbers in the middle. And a good hardware firewall.
Be more afraid of trojans/keyloggers.
1101 (13337)
1281991 2012-06-19 09:39:00 ...I worked in a company that enforced a pretty strict password policy...

And how many log-on attempts did they allow you before you were locked out??\

If the number is kept small and you are locked out for ever-increasing intervals, passwords can be as weak as.
decibel (11645)
1281992 2012-06-19 11:24:00 For my usual passwords I have a pass phrase like

Hollywood has stars like Tom Hanks

To convert to HhslTH and then a number phrase.

I am a geek so I have used the Major memory system (eg 1=T or D 2=N etc) and convert the site I am connecting to into a number sequence. And then add a special character at the end.

It is surprisingly easy once you have the method down pat.

It allows for memorable, caps numbers and special characters and its stable.

But like I said I am a bit of a geek...


Doesnt work against the rolling password changes though.

Telecom had that on a lot of their apps and it was crazy cause you have like 30 apps to remember passwords for and rotating passwords. Can't reuse same pass for last 12 changes etc..
adslgeek (14687)
1281993 2012-06-19 23:39:00 All password policies are banal.
XKCD got it right with this comic (imgs.xkcd.com)
tmrafi (5179)
1 2