4 ms·
I'm curious how far practical implementations of the NIST guidelines take the advice to preempt dictionary attacks by not letting users choose known bad choices
by Asdfbla 9y ago
I'm curious how far practical implementations of the NIST guidelines take the advice to preempt dictionary attacks by not letting users choose known bad choices. Of course the advice is perfectly reasonable, but when a user can't choose 'password', they will probably try 'password1' - not really much safer against the usual password cracking software, do you check that too then? But I guess the article mentions that dilemma too. I guess it's again a tradeoff between not annoying the user and annoying the password cracker sufficiently. :)
- proaralyst 9y agopassword1 and reasonable mutations of password are probably present in the top 10000 passwords. If that's not the case in general, a good benchmark would be 'can hashcat break this given a reasonable mutation pattern'. The zxcvbn project pretty much provides that.