3 ms·
A usable and secure password policy backed by science
- bradknowles 6y ago12 characters? Even if they’re completely randomly chosen amongst the base64 printable character set, that’s only 12 * 6 = 72 bits of entropy. Easily guessable/crackable by modern tools, very quickly.
- chokeartist 6y agoYes, in a few scenarios I see that possible: A) You can spam attempts to the login endpoint, at an unlimited rate (not likely). or B) You have a dump of their user/pw database, unsalted (not likely). In other words, assuming proper foundational security practices, 12 char/72 bits is a good balance between usability (ability to remember / type) and security.
- DarthGhandi 6y ago> Easily guessable/crackable by modern tools, very quickly. Spot the person who doesn't hash passwords correctly. A keyspace of 4.7 x 10^21, even with a typical modern 8 gpu cracking rig running 24/7 would take millennia to crack. If you were talking about sha2 then yeah, but pbkdf or argon2, no way. You'd be lucky to get 7000 h/s out of a modern gpu against argon with standard parameters.
- m463 6y agochecked out their sample and saw these "localizations": :) ignoredWords: // list of words that should count for nothing in the password ["pittsburgh", "steelers", "stillers", "penguins", "pens", "pirates", "bucs", "carnegie", "mellon", "university"], forbiddenPasswords: // list of passwords that should be rejected ["123456", "password", "12345", "12345678", "qwerty", "1234567890", "1234", "baseball", "dragon", "football", "1234567", "monkey", "letmein", "abc123", "111111", "mustang", "access", "shadow", "master", "michael", "superman", "696969", "123123", "batman", "trustno1"],