Password Complexity, Good or bad?
-
No matter what they say... length matters
-
@brianlittlejohn said:
No matter what they say... length matters
Yes, I purposely went there. I'm heading home now, latter
-
@travisdh1 said:
Length matters, everything else is a flying spaghetti monster. If you really want to know why, you've got a LOT of reading to do, and probably more math than you've ever wanted to understand, let alone do.
I also agree with that.
I am just saying isn't
thisisalongpassword
weaker than
thisisa@longpassword
-
@BRRABill said:
@travisdh1 said:
Length matters, everything else is a flying spaghetti monster. If you really want to know why, you've got a LOT of reading to do, and probably more math than you've ever wanted to understand, let alone do.
I also agree with that.
I am just saying isn't
thisisalongpassword
weaker than
thisisa@longpassword
Yes, of course it is. but thisisalongpassword is way better than P@ssw0rd
-
@Dashrender said:
Yes, of course it is. but thisisalongpassword is way better than P@ssw0rd
I originally was questioning @scottalanmiller that
password
and
P@ssw0rdare the same to a computer.
Not arguing anything here. Agree with it all.
-
@Dashrender said:
thisisalongpassword
according to howsecureismypassword.com
thisisalongpassword
and P@ssw0rd
-
@BRRABill said:
@Dashrender said:
Yes, of course it is. but thisisalongpassword is way better than P@ssw0rd
I originally was questioning @scottalanmiller that
password
and
P@ssw0rdare the same to a computer.
Not arguing anything here. Agree with it all.
He was over simplifying it, sure. But both would be in a pre defined dictionary which would take seconds to crack so he does have that on his side.
-
http://howsecureismypassword.com/
Appears to be offline
-
-
thisisalongpassword = 607 million years
thisisalongpasswor@ = 3 trillion years
-
@BRRABill said:
@Breffni-Potter said:
http://howsecureismypassword.com/
Appears to be offline
.NET
whoops
-
-
@BRRABill said:
thisisalongpassword = 607 million years
thisisalongpasswor@ = 3 trillion years
Is there a real difference? A meaningful difference?
-
-
@Dashrender said:
Is there a real difference? A meaningful difference?
Yes.
I plan to live between those two numbers, so I need the stronger password.
-
@BRRABill said:
@Dashrender said:
Is there a real difference? A meaningful difference?
Yes.
I plan to live between those two numbers, so I need the stronger password.
Just change it at least once between now and then and you should be fine.
-
@Dashrender said:
Is there a real difference? A meaningful difference?
My point is that just adding a capital or symbol adds a lot of complexity to the password. It can make a big difference when dealing with shorter passwords. (Say 12 or less.) Why totally take them out of the equation? Especially at the beginning or end of the passphrase? Or on sites that don't allow longer passwords for whatever reason.
-
@Dashrender said:
Just change it at least once between now and then and you should be fine.
I was planning to just add another @ sign but apparently that is a no-no.
-
@BRRABill said:
@Dashrender said:
Is there a real difference? A meaningful difference?
My point is that just adding a capital or symbol adds a lot of complexity to the password. It can make a big difference when dealing with shorter passwords. (Say 12 or less.) Why totally take them out of the equation? Especially at the beginning or end of the passphrase? Or on sites that don't allow longer passwords for whatever reason.
No one ever said take them out.. just that they aren't a requirement.
the general belief is that the more requirements you put on users, the more they will fight you. So do 12+ and have no requirements - you can suggest that they put in caps, numbers, special characters.. but not required.
-
@Dashrender said:
No one ever said take them out.. just that they aren't a requirement.
the general belief is that the more requirements you put on users, the more they will fight you. So do 12+ and have no requirements - you can suggest that they put in caps, numbers, special characters.. but not required.
Got it.
I'm glad you and I had this little discussion!