Author Topic: How Complex Does Your Password Have To Be?  (Read 7051 times)

Offline skyguy918

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Mar 2011
  • Posts: 4081
  • Total likes: 837
  • DansDeals.com Hat Tips 1
  • Gender: Male
    • View Profile
  • Location: Queens, NY
Re: How Complex Does Your Password Have To Be?
« Reply #20 on: October 26, 2017, 05:28:39 PM »
True. But who is able to use a 20 character password without having to write it down? Or he will use something that is significant to him that he will remember. Those are both bigger security risks. An 8 character, with numbers, special characters, capitalization, that is random and memorable is ultimately a lot more secure.

Read up on how long it takes to crack such a password that is truly random. :)
What you're saying is incorrect. That was the point of the XKCD cartoon above. String together 4 random words that total 20 characters and your password is both vastly more difficult to crack, and easier to remember than 8 random characters.

Offline yelped

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: Mar 2015
  • Posts: 11491
  • Total likes: 4199
  • DansDeals.com Hat Tips 43
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #21 on: October 26, 2017, 05:39:02 PM »
What you're saying is incorrect. That was the point of the XKCD cartoon above. String together 4 random words that total 20 characters and your password is both vastly more difficult to crack, and easier to remember than 8 random characters.
Sorry, I missed that. You are right.

Offline Zalc

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Nov 2014
  • Posts: 1804
  • Total likes: 160
  • DansDeals.com Hat Tips 0
    • View Profile
  • Location: USA
Re: How Complex Does Your Password Have To Be?
« Reply #22 on: October 26, 2017, 05:46:38 PM »


https://xkcd.com/936/

https://explainxkcd.com/936/
Some cracker have started using dictionaries as sources to guess from, with each word treated as a letter.

In effect this becomes faster to crack if you use words directly from the dictionary, even if you use common substitutions (E.G. O-0).

But it should be pretty easy to make one of the words a non-dictionary word (Yiddish, anyone?) or incorrect punctuation.

Offline skyguy918

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Mar 2011
  • Posts: 4081
  • Total likes: 837
  • DansDeals.com Hat Tips 1
  • Gender: Male
    • View Profile
  • Location: Queens, NY
Re: How Complex Does Your Password Have To Be?
« Reply #23 on: October 26, 2017, 05:54:14 PM »
Some cracker have started using dictionaries as sources to guess from, with each word treated as a letter.

In effect this becomes faster to crack if you use words directly from the dictionary, even if you use common substitutions (E.G. O-0).

But it should be pretty easy to make one of the words a non-dictionary word (Yiddish, anyone?) or incorrect punctuation.
That changes nothing. Do you know how many words are in the dictionary? Compare that to the maximum 96 character set for each character of a 6 or 8 character password.

ETA: Although I was actually going to mention Yiddish. Makes it super easy to be both easy to remember, as well as practically uncrackable. Just remember to use a phrase, not just a single word.

Offline Zalc

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Nov 2014
  • Posts: 1804
  • Total likes: 160
  • DansDeals.com Hat Tips 0
    • View Profile
  • Location: USA
Re: How Complex Does Your Password Have To Be?
« Reply #24 on: October 26, 2017, 05:56:06 PM »
That changes nothing. Do you know how many words are in the dictionary? Compare that to the maximum 96 character set for each character of a 6 or 8 character password.
Yes, but if you limit the guesses to the max of the password field, say 20 characters, you mitigate much of this.

What is the standard max length for a good website?

Offline aygart

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: May 2008
  • Posts: 18945
  • Total likes: 15074
  • DansDeals.com Hat Tips 14
    • View Profile
    • Lower Watt Energy Brokers
  • Programs: www.lowerwatt.com
Re: How Complex Does Your Password Have To Be?
« Reply #25 on: October 26, 2017, 05:56:45 PM »
Some cracker have started using dictionaries as sources to guess from, with each word treated as a letter.

In effect this becomes faster to crack if you use words directly from the dictionary, even if you use common substitutions (E.G. O-0).

But it should be pretty easy to make one of the words a non-dictionary word (Yiddish, anyone?) or incorrect punctuation.

I often use various mixes of Hebrew words and gematria. Sometimes is tranliterate and sometimes use the keys of the Hebrew keyboard to type English for the corresponding gibberish.
Feelings don't care about your facts

Offline ExGingi

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: Nov 2015
  • Posts: 17972
  • Total likes: 8184
  • DansDeals.com Hat Tips 19
    • View Profile
  • Location: 770
  • Programs: בשורת הגאולה. From Exile to Redemption. GIYF. AAdvantage Executive PlatinumŽ
Re: How Complex Does Your Password Have To Be?
« Reply #26 on: October 26, 2017, 06:02:33 PM »
I use a long sentence with spaces (for places that allow spaces and as a lastpass password). If spaces are allowed I believe it adds a level of security, as well as being able to use a loooong memorable sentence that might be meaningless to others.
I've been waiting over 5 years with bated breath for someone to say that!
-- Dan

Offline skyguy918

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Mar 2011
  • Posts: 4081
  • Total likes: 837
  • DansDeals.com Hat Tips 1
  • Gender: Male
    • View Profile
  • Location: Queens, NY
Re: How Complex Does Your Password Have To Be?
« Reply #27 on: October 26, 2017, 06:06:31 PM »
Yes, but if you limit the guesses to the max of the password field, say 20 characters, you mitigate much of this.

What is the standard max length for a good website?
Not sure why you think that would change much of anything. Go back and read the article Boruch999 linked to. I guarantee you the dictionary based methods were included in their research, and they still found that length is the best indicator of strength.

Offline ChaimMoskowitz

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jun 2014
  • Posts: 7232
  • Total likes: 1099
  • DansDeals.com Hat Tips 1
  • Gender: Female
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #28 on: October 26, 2017, 06:54:16 PM »
What is the standard max length for a good website?
18-20?
I just found a new supply of forks!

Offline yuneeq

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jan 2013
  • Posts: 8904
  • Total likes: 4084
  • DansDeals.com Hat Tips 10
  • Gender: Male
    • View Profile
  • Location: NJ
Re: How Complex Does Your Password Have To Be?
« Reply #29 on: October 26, 2017, 07:04:39 PM »
All of you discussing how you formulate your passwords are obviously reusing the same passwords on multiple websites, (unless you claim to remember 100+ passwords.)
This is the WORST idea you can have.
Visibly Jewish

Offline ChaimMoskowitz

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jun 2014
  • Posts: 7232
  • Total likes: 1099
  • DansDeals.com Hat Tips 1
  • Gender: Female
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #30 on: October 26, 2017, 07:12:52 PM »
All of you discussing how you formulate your passwords are obviously reusing the same passwords on multiple websites, (unless you claim to remember 100+ passwords.)
This is the WORST idea you can have.
+1
I just found a new supply of forks!

Offline skyguy918

  • Dansdeals Presidential Platinum Elite
  • ********
  • Join Date: Mar 2011
  • Posts: 4081
  • Total likes: 837
  • DansDeals.com Hat Tips 1
  • Gender: Male
    • View Profile
  • Location: Queens, NY
Re: How Complex Does Your Password Have To Be?
« Reply #31 on: October 26, 2017, 07:26:00 PM »
All of you discussing how you formulate your passwords are obviously reusing the same passwords on multiple websites, (unless you claim to remember 100+ passwords.)
This is the WORST idea you can have.
Speak for yourself. When you use an password manager, you need a master password. Same rules for good passwords apply there.

Offline ChaimMoskowitz

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jun 2014
  • Posts: 7232
  • Total likes: 1099
  • DansDeals.com Hat Tips 1
  • Gender: Female
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #32 on: October 26, 2017, 07:30:19 PM »
Speak for yourself. When you use an password manager, you need a master password. Same rules for good passwords apply there.
This one is pretty simple to crack: 3Nz@g0DILJuPY!cFYXeSs6EJ
I just found a new supply of forks!

Offline mmgfarb

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Dec 2015
  • Posts: 8401
  • Total likes: 1120
  • DansDeals.com Hat Tips 4
    • View Profile
Re: How Complex Does Your Password Have To Be?
« Reply #33 on: October 26, 2017, 07:47:10 PM »
It's not just about length of the password but also what the makeup of the password is, nobody really sits there and tries to brute force passwords anymore, they use databases of already cracked passwords and run those through instead. The idea of using Hebrew or Yiddish phrases is actually a really good idea (because they most likely aren't in the data bases being used) as is lastpass. This is a great video if you want to know more about how passwords are actually cracked.
"JS [is] a fetid cesspool of unvarnished linguistic manure, with lots of useless drivel and post-padding." -Moishebatchy

Offline Zalc

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Nov 2014
  • Posts: 1804
  • Total likes: 160
  • DansDeals.com Hat Tips 0
    • View Profile
  • Location: USA
Re: How Complex Does Your Password Have To Be?
« Reply #34 on: October 26, 2017, 07:56:34 PM »
All of you discussing how you formulate your passwords are obviously reusing the same passwords on multiple websites, (unless you claim to remember 100+ passwords.)
This is the WORST idea you can have.
What do use?

I use lastpass. No way I am remembering 100+ strong passwords.

The new family sharing plan looks pretty good.

Offline yuneeq

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jan 2013
  • Posts: 8904
  • Total likes: 4084
  • DansDeals.com Hat Tips 10
  • Gender: Male
    • View Profile
  • Location: NJ
Re: How Complex Does Your Password Have To Be?
« Reply #35 on: October 26, 2017, 08:17:23 PM »
What do use?

I use lastpass. No way I am remembering 100+ strong passwords.

The new family sharing plan looks pretty good.

I also use Lastpass
Visibly Jewish

Offline aygart

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: May 2008
  • Posts: 18945
  • Total likes: 15074
  • DansDeals.com Hat Tips 14
    • View Profile
    • Lower Watt Energy Brokers
  • Programs: www.lowerwatt.com
Re: How Complex Does Your Password Have To Be?
« Reply #36 on: October 26, 2017, 08:47:02 PM »
What do use?

I use lastpass. No way I am remembering 100+ strong passwords.

The new family sharing plan looks pretty good.
I also use Lastpass
I used to use it
Just got a Firefox notification that LastPass is not compatible with the current version.
Feelings don't care about your facts

Offline Zalc

  • Dansdeals Lifetime Platinum Elite
  • *******
  • Join Date: Nov 2014
  • Posts: 1804
  • Total likes: 160
  • DansDeals.com Hat Tips 0
    • View Profile
  • Location: USA

Offline ChaimMoskowitz

  • Dansdeals Lifetime Presidential Platinum Elite
  • *********
  • Join Date: Jun 2014
  • Posts: 7232
  • Total likes: 1099
  • DansDeals.com Hat Tips 1
  • Gender: Female
    • View Profile
I just found a new supply of forks!

Offline aygart

  • Dansdeals Lifetime 10K Presidential Platinum Elite
  • *******
  • Join Date: May 2008
  • Posts: 18945
  • Total likes: 15074
  • DansDeals.com Hat Tips 14
    • View Profile
    • Lower Watt Energy Brokers
  • Programs: www.lowerwatt.com
Re: How Complex Does Your Password Have To Be?
« Reply #39 on: October 26, 2017, 09:18:57 PM »
How many times should I try it?  :)
Until it works
Feelings don't care about your facts