4 ms·
> facepalm. You can't use both? I do. This is horrible advice if taken on face value. Of course you can! I think you are taking many of my statements much too
by m8urn 13y ago
> facepalm. You can't use both? I do. This is horrible advice if taken on face value.
Of course you can!
I think you are taking many of my statements much too literally and misinterpreting the perspective of this article. Of course a long, completely random password made up of multiple character sets will always be the strongest password, but that really isn't the point of this article and it really isn't the most practical advice for most users.
There is a big difference between addressing where we need to be and moving away from where we actually are. Short passwords are not strong enough no matter how random they are. Therefore, I personally would rather see users out there focus on making longer passwords rather than focusing on random passwords. The typical user is much more likely to memorize a less random but longer password than trying to memorize an 8-character random password. I didn't mean to imply that randomness is bad, and I thought that most people got that from my article.
> Let me stop here and say that I can check ALL of the above in less time than it would take to check all variations of 3 characters using alpha, numeric, and common special characters.
These are all valid points and I could have gone into great detail on all the different ways our passwords could be cracked, but that just isn't the point of the article. I also didn't cover other things such as avoiding password reuse, regularly changing passwords, etc., but that doesn't make them any less valid and I cover them regularly through my other blog posts.
> And please stop dismissing the issue by repeating the words "brute force"
Not really sure what you mean by this or what issue you think I have dismissed by mentioning brute force. Brute force attacks are by n o means dismissing anything as they have become increasingly effective with ever-increasing computing power. Nevertheless, if an attacker has to assume that you will be using all character sets, the effort to crack your password grows exponentially with the length of your password.
- jere 13y agoI guess I don't really disagree with you on that, especially if you're specifically targeting nontechnical users. However, the thought of someone reading this and choosing something like an all numeric password does freak me out because.... >Not really sure what you mean by this or what issue you think I have dismissed by mentioning brute force. Let me explain through analogy. I've often heard the story that a company will request a penetration tests and then restrict what can be done: "you can attack using method X, but not Y. A hacker wouldn't use Y." That's a silly perspective, right? A black hat hacker is going to use any means available. When you say brute force, you seem to be specifying the method by which attackers will come at your password (and it's certainly not just you, many other people are repeating the meme). I think that's the wrong way to look at it. Perhaps the confusion arises because you're making the assumption that someone will use some off the shelf, automated cracking software. That's reasonable. But automated != brute force. Again, if I were to write a cracker, it would first grab low hanging fruit. I've already given examples. Having a long password doesn't save you in that situation. That's why we think in terms of entropy. >Nevertheless, if an attacker has to assume that you will be using all character sets, the effort to crack your password grows exponentially with the length of your password. Agreed, but my point is they don't have to make that assumption. We don't get to decide what assumptions they start with.