6 ms·
That's not true and is horsecrap. a) check length of password. Length < 6 = fail. Length < 10 = complexity requirement. Length < 15 = less complexity requireme
by GrandMasterBirt 16y ago
That's not true and is horsecrap.
a) check length of password. Length < 6 = fail. Length < 10 = complexity requirement. Length < 15 = less complexity requirement. Length > 15 = secure.
b) ALWAYS do a dictionary lookup on the password. A dic lookup vs a dic attack is cheap. Hell the dic can be stored in memory in a hash map... even with misspellings, we don't even need to be 100% accurate either. Once you have that, basically check complexity: 1 word = no good. 2 words = ok, add a special character in there and a caps. 3 words = great. 3 words + special characters = awesome. etc.
Anyone can make one of these in a few hrs. and give error messages like:
"Your password is too short"
"your password is too simple for it's length, either make it longer or add special characters, numbers, and capitol letters"
"your password is made up of a single word or easily obtainable information about you based on information we have in our system, please change the words used or add more of them"
This means: (a) people understand why password is rejected and (b) people have choices and (c) increases probability that people won't forget their password.
Oh and any system that limits passwords to < 50 characters can fo fk themselves. Too bad ADP (paystub) has a policy of 6-12 characters. Thats right limitations, and I have to use that crap. Is a 4000 byte database column that expansive nowdays?
Furthermore... Changing password every 1-3-6 months is also bad. WHY? Simple, very very simple: 99% of the time you will have one of the following situations:
- The same password is used + an extra 1 or 2 characters.
- The same password is used + different capitalizations.
- A different password is used + post-it note.
- The user will forget their password immediately.
The TRUE answer to the reason why it policies are the way they are is because people don't want to think. "Tom did it this way, it must be secure." "I don't really understand it, so whatever, its the standard, it must work."
To make passwords secure they need to enact the policies I stated + a second factor for authentication. If you log in from an "unknown" location (a new one) just send them an email, or sms, or something that gives some key to enter to authorize. This will work in letting people know there is a breach, change pw on need, don't make ppl change passwords nonestop. Lots of advantages.
Wow writing this I feel like we need a startup that provides this exact solution. One question for the fellas who know more... how hard is it to spoof someone's ip without them knowing (internal network or external)
- iuguy 16y ago> That's not true and is horsecrap. You must be fun at parties. You do realise that a password of AAAAAAAAAAAAAAAA would be considered completely secure by your system, right? For your second point your dictionary checking algorithm is only as good as your dictionary. If your dictionary is too small then you're not going to do much. It won't do much good for multilingual users either. <snip rant about changing passwords every now and again> So are you proposing that people don't periodically change their passwords? As for spoofing the IP, it depends on where you are and where the target is. If for example you're both on the same internal network, are NATted and your system's on the Internet then it won't distinguish between the two IP addresses. The same applies if both your and the spoofer are going through a proxy, or the spoofer is between you and them (although it is harder to do than just sitting behind the same NAT gateway it is doable).
- sukuriant 16y agoHow is AAAAAAAAAAAAAAAA not a secure password? Unless you're standing over the person's shoulder, how are you going to know that their 16 letter password is all one letter?
- iuguy 16y agoYou're not going to know anything about their password unless it's leaked in some way (e.g. maximum length on a password change screen, character set etc. or cryptographic leaks). However it's wrong to assume the approach an adversary will take when you know nothing about the adversary in question. If I exhaust a 16 character space with alphanumeric passwords and pull out aaaaa as one, am I going to add mixed alphanumeric to my list and start again or am I going to check variants on AaAaA up to a certain length? Personally I don't know which I'd choose, it'd be dependent on the situation (but I've done both on penetration tests).
- sukuriant 16y agoThat's reasonable; but, they probably aren't going to know the length of the password either, so they might go through a great many other tests before they reach A16. Of course, the person trying to discern a person's password may follow a DFS approach before a BFS approach, and that password would be quickly compromised, but I don't see that happening. Note: In the real world, I wouldn't encourage anyone to have that as a password. This is more of an academic curiosity.