Our server costs ~$56 per month to run. Please consider donating or becoming a Patron to help keep the site running. Help us gain new members by following us on Twitter and liking our page on Facebook!
Current time: May 21, 2024, 2:06 pm

Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
On Password Strength
#16
RE: On Password Strength
Yes, I based my method somewhat on Randall's, but mine isn't susceptible to what should probably be termed "known-method attacks". In essence, if an attacker knows something about your password, then generally speaking it is easier to attack it. For instance, if I knew that someone's password was using Randall's method, I wouldn't run a bog-standard brute-force algorithm at it. Instead, I'd get a large dictionary of words, and then just run through all possible combinations of 4 words.

Of course, the chances of an attacker knowing you use Randall's method are quite remote (at least, they should be), so his method is still "more secure" in a pure brute-force scenario. However, the fact that known-method attacks exist, and could potentially break one of Randall's passwords is less time than a standard password should be worrying. Hence, my method tries to protect against these sorts of attacks, by using the element of randomness, but putting it into a proper sentence form. So you still have words from the dictionary, but some of them might be capitalised, and others might be followed by some punctuation symbol, etc. The number of brute-force attempts thus becomes the number of possible sentences that you can have, making such attacks infeasible.
Reply



Messages In This Thread
On Password Strength - by Tiberius - March 28, 2012 at 1:25 pm
RE: On Password Strength - by Violet - March 28, 2012 at 1:46 pm
RE: On Password Strength - by Shell B - March 28, 2012 at 1:50 pm
RE: On Password Strength - by Violet - March 28, 2012 at 1:51 pm
RE: On Password Strength - by Doubting Thomas - March 28, 2012 at 2:01 pm
RE: On Password Strength - by NoMoreFaith - March 28, 2012 at 2:10 pm
RE: On Password Strength - by Violet - March 28, 2012 at 2:28 pm
RE: On Password Strength - by Tiberius - March 28, 2012 at 2:12 pm
RE: On Password Strength - by Jackalope - March 28, 2012 at 3:03 pm
RE: On Password Strength - by Doubting Thomas - March 28, 2012 at 4:47 pm
RE: On Password Strength - by Cinjin - March 28, 2012 at 4:54 pm
RE: On Password Strength - by Jackalope - March 28, 2012 at 4:57 pm
RE: On Password Strength - by Tiberius - March 28, 2012 at 4:59 pm
RE: On Password Strength - by Doubting Thomas - March 28, 2012 at 5:19 pm
RE: On Password Strength - by Rob - March 29, 2012 at 11:39 am
RE: On Password Strength - by Tiberius - March 31, 2012 at 8:17 am
RE: On Password Strength - by KichigaiNeko - March 31, 2012 at 8:47 am
RE: On Password Strength - by Tiberius - March 31, 2012 at 8:49 am
RE: On Password Strength - by KichigaiNeko - March 31, 2012 at 10:26 am
RE: On Password Strength - by Tiberius - March 31, 2012 at 10:34 am
RE: On Password Strength - by KichigaiNeko - March 31, 2012 at 10:35 am
RE: On Password Strength - by Tiberius - March 31, 2012 at 10:38 am
RE: On Password Strength - by KichigaiNeko - March 31, 2012 at 10:38 am
RE: On Password Strength - by Tiberius - March 31, 2012 at 10:42 am
RE: On Password Strength - by KichigaiNeko - April 1, 2012 at 6:33 am
RE: On Password Strength - by Atheist Anarchist - April 1, 2012 at 5:48 am
RE: On Password Strength - by Atheist Anarchist - April 1, 2012 at 7:18 am
RE: On Password Strength - by Napoléon - April 2, 2012 at 7:01 am
RE: On Password Strength - by KichigaiNeko - April 1, 2012 at 9:07 am
RE: On Password Strength - by Rob - April 2, 2012 at 6:58 am
RE: On Password Strength - by KichigaiNeko - April 2, 2012 at 7:00 am
RE: On Password Strength - by Autumnlicious - April 2, 2012 at 4:12 pm
RE: On Password Strength - by Napoléon - April 2, 2012 at 4:28 pm
RE: On Password Strength - by Autumnlicious - April 2, 2012 at 5:33 pm
RE: On Password Strength - by Napoléon - April 2, 2012 at 5:43 pm
RE: On Password Strength - by CaptainPicard - April 2, 2012 at 8:40 pm
RE: On Password Strength - by Napoléon - April 3, 2012 at 8:36 am
RE: On Password Strength - by SavageNerdz - April 3, 2012 at 12:09 am
RE: On Password Strength - by Tiberius - April 3, 2012 at 8:34 am
RE: On Password Strength - by Tiberius - April 3, 2012 at 8:39 am
RE: On Password Strength - by Napoléon - April 3, 2012 at 8:41 am

Possibly Related Threads...
Thread Author Replies Views Last Post
  Change your Ebay password! Autumnlicious 5 1008 May 27, 2014 at 11:23 am
Last Post: vorlon13



Users browsing this thread: 2 Guest(s)