3 ms·
I wouldn't, I would apply something like this http://www.passwordmeter.com/ http://www.passwordmeter.com/ and show the user how secure or insecure their passwor
by x1 14y ago
I wouldn't, I would apply something like this http://www.passwordmeter.com/ http://www.passwordmeter.com/ and show the user how secure or insecure their password is. Depending on the service they are using maybe only allow passwords at Strong or better but base that off the complexity of the passwords. %09(0m is stronger than minneapolisminnesota
- LinaLauneBaer 14y agoDoesn't the strength of a password also depend on the cardinality of the underlying alphabet? So your example makes only sense when you also say something about the used alphabet or am I missing something here?
- Dove 14y agoSort of. The strength of a password, at the most basic level, is based on the number of passwords it could have been. That is to say, the number of live possibilities in your password-generating algorithm. In theory, large alphabets and long passwords lead to increased password strength because they mean your password could have been many other things. In practice, the vast majority of those other things were never live possibilities, so the password is not that strong even if it is long or the symbol set is large. For example, suppose you choose to base your password on your dog's name, Rover. This is one of maybe half a dozen likely choices for you, so is not a strong password. If you modify it for length and symbol set into Fetch4meRover!, this is still one of maybe a dozen things you would have chosen to do with the name, so is still not that strong in spite of the length and character set. In general, you should not trust yourself to generate random information, and particularly passwords. Use a script to randomly generate a password -- a script with a known large number of live possibilities. This is the only way to ensure those possibilities -- the ones that make a password secure -- were ever actually live.