3 ms·
A fifteen letter password that is a mixture of letters, numbers and symbols is only 56% complex? That's bonkers. What's the point of measuring complexity if y
by kgen 14y ago
A fifteen letter password that is a mixture of letters, numbers and symbols is only 56% complex? That's bonkers. What's the point of measuring complexity if you aren't going to be able to remember the password?
- danpalmer 14y agoThe complexity is based on the minimum required to be valid (~44%) being an 8 character password with upper, lower and numbers. That is really the absolute minimum anyone should be using now I think. As for your password scoring 56%, that's not too bad. But adding more characters has more of an effect that adding a wider range of characters. This is how it should be.
- byoung2 14y agoIt depends on what the password is for. I think the more complex passwords are appropriate for root passwords or databases, but for user passwords, you would have to educate users that anything above a certain threshold (say 30%) is good enough. My attempt fJ6&$h12@ was 40% and $Y8th&t%k^! was 48% and these are way more complex than most people need to secure email or log in to a web app. Above a certain level, and they'll write it on a sticky note.
- danpalmer 14y agoThose two passwords aren't too bad, but they aren't amazing. They are only 9 characters and length matters far more than the character sets you include. This is the big misconception many users have, and it's promoted by all the password strength meters that get this wrong. Complexify is my attempt at providing a better metric.
- chc 14y agoPasswords don't have to be unmemorable to be hard to crack. For example, "Can you remember this?" has 87% complexity and "Bet you can remember this one" has 100% complexity.