3 ms·
A sensible password-selection policy really only has two principles: 1. It shouldn't be in a dictionary, so that the only option is brute force 2. It should be
by billybob 14y ago
A sensible password-selection policy really only has two principles:
1. It shouldn't be in a dictionary, so that the only option is brute force
2. It should be very hard to brute force
#1 means "don't use anything in this guy's list."
For #2, the concept of "password haystacks" is useful:
https://www.grc.com/haystack.htm https://www.grc.com/haystack.htm
- DanBC 14y agoSteve Gibson is not considered expert: (http://radsoft.net/rants/20010714,00.shtml http://radsoft.net/rants/20010714,00.shtml) (http://www.groklaw.net/article.php?story=20060113111825193 http://www.groklaw.net/article.php?story=20060113111825193) (http://attrition.org/errata/charlatan/steve_gibson/ http://attrition.org/errata/charlatan/steve_gibson/) etc etc.
- billybob 14y agoIs there something specifically wrong with the concept of password haystacks? I understand it as "force the attacker to search an extremely large potential keyspace." The tool I linked to simply calculates the keyspace that a given candidate password is in.