5 ms·
It occured to me last night that password strength is a predatory system similar to capitalism. My bank recently reduced it's max password length from 20 chara
by featherverse 9y ago
It occured to me last night that password strength is a predatory system similar to capitalism.
My bank recently reduced it's max password length from 20 characters to 15, so in an E-mail I was writing to the CEO demanding they fix it, I was recommending improvements and I realize that an 18 character password SHOULD be minimum, however...
If an 18 character password is minimum that actually reduces the length of brute force attacks. If the minimum length is 8 characters and the maximum something ridiculous like 64, then people with 32-64 characters will have the strongest passwords.
However, this relies on the assumption that lots of people will be using weak passwords, the brute forcers are going to target and exploit those people first. The number of possible permutations are increased by allowing weaker passwords, but that isn't enough. If everyone uses 18 char or greater passwords then brute forcers will start their searches at 18 characters so it would matter if 8 characters are allowed.
Just some food for thought, and reason to encourage the use of stronger passwords than the recommended 180 bits. If the system supports 64 characters, might as well use 64 characters. And if it doesn't support 64 characters, fix it.
- Terr_ 9y agoOr to cheekily summarize your post: "You don't need to outrun the bear/hacker. You just need to outrun the other people."
- daveFNbuck 9y agoWith an alphabet size of A, the number of passwords with N characters is equal to A-1 times the number of passwords with fewer than N characters, plus 1. This means that if you allow at least uppercase and lowercase letters in the password, setting a minimum decreases the search space by less than 2%, assuming the minimum equals the maximum. If we even increase the maximum a tiny bit above the minimum, this decreases exponentially. Allowing a length of 8-20 instead of 18-20 only increases the search space by 0.0007%. So you have to ask yourself whether that tiny fraction of a percent more security for you against brute force attackers (which a proper password of that length is already secure enough against) is really worth having your money in a bank with easy to hack accounts. As a customer, part of the cost of all those hacked accounts is going to find its way to you eventually.