The truth about password strength

  • Thread starter FlexGunship
  • Start date
  • Tags
    Strength
In summary: Password length is up to 3 minutes, with a maximum of 8 characters. Passwords must be random, and must not include personal information like your name, date of birth, or child's name. If you forget your password, you must change it immediately. Passwords must be 3 minutes long, and must be changed every 3 months.
  • #1
FlexGunship
Gold Member
426
8
Moderator's note: A reminder to all to use common sense when duplicating others' intellectual property.

XKCD, for example, requires some sort of attribution attached to postings of its comics; e.g. a link to the comic. (And, thankfully, XKCD does permit its images to be hotlinked)

password_strength.png
 
Last edited by a moderator:
Physics news on Phys.org
  • #2
There goes my password. It was correcthorsebatterystaple. This is the worse thing to happen to me since a quantum computer successfully factored 15 into primes and broke my private key.
 
  • #3
Jimmy Snyder said:
There goes my password. It was correcthorsebatterystaple.

Hah, damn... I just got done changing my 57 passwords to that. Time to change them to something else. I can't have the same password as everyone.
 
  • #4
Instead of memorizing the letters, numbers, etc, it's better to memorize some tune and the dance steps to that tune - except your fingers do the dancing instead of your legs.

Except that doesn't work for the classified computers at work. Your password can't have any patterns in it. They don't even allow patterns that match legal moves for the Knight in chess or even allow a castling move pattern and they definitely don't allow any of the legal moves in Go or Chinese Checkers. We have a theory that the rules for passwords at work have become so elaborate that there's only one possible password that's allowable and that everyone is actually using the same password, but we can't verify it because we can't ever tell anyone our password.
 
Last edited:
  • #5
BobG said:
Instead of memorizing the letters, numbers, etc, it's better to memorize some tune and the dance steps to that tune - except your fingers do the dancing instead of your legs.

How mindlessly poetic of you.

My fingers play Dance Dance Revolution on the keyboard when I'm entering my password : "upupdowndownleftrightleftrightBAselectstart."
 
  • #6
At my last job, the rules for passwords were so elaborate that there was no way to remember them. We all just wrote them down and left them on our desks.
 
  • #7
Jimmy Snyder said:
At my last job, the rules for passwords were so elaborate that there was no way to remember them. We all just wrote them down and left them on our desks.

That's my current job. It's absurd.
 
  • #8
FlexGunship said:
How mindlessly poetic of you.

My fingers play Dance Dance Revolution on the keyboard when I'm entering my password : "upupdowndownleftrightleftrightBAselectstart."

My fingers prefer Fred Astaire dancing to "You're All the World to Me" from "Royal Wedding".
 
  • #9
It's not all that hard to memorize a random sequence of 8 characters if you spend a few minutes practicing it. :-p
 
  • #10
Hurkyl said:
It's not all that hard to memorize a random sequence of 8 characters if you spend a few minutes practicing it. :-p

Your passwords are only 8 characters long?!

Passwords have to be at least 3 minutes where I work!
 
  • #11
Long ago, you could use special symbols in password fields but that is quickly going away.

I also used to move my hand position about the keyboard and type passwords.

Maybe one index fingers now on G and H instead of F and J or maybe shift it up or down.
 
  • #12
Hurkyl said:
It's not all that hard to memorize a random sequence of 8 characters if you spend a few minutes practicing it. :-p
I failed to mention we had to change them every three months.
 
  • #13
Jimmy Snyder said:
I failed to mention we had to change them every three months.

So your passwords are:

password1
password2
password3
...
password[INT((X-1)/3)+1] where "X" is the number of months that you've been employed?
 
  • #14
Ah! This xkcd is so excellent.
Yes! Always please use nonsensical sentences in your passwords! Easy to remember, with the benefit of not being found in any book, and if you stray from grammar, you're protected by another layer when in the future computers will be able to guess sentences and reference books.
 
  • #15
For a time, I worked for an outfit in which the technical director was a clueless martinet, and his rules for formatting and changing passwords were draconian and ill-advised. Yes, we techs had trade-secrets on our computers, but we were in the field 99% of the time and didn't have the luxury of nice hiding places, like a boring book on a shelf in the office in which you could jot your latest password.

Years later, I became the network administrator for a very large (by Maine standards) ophthalmic practice and I urged people to use strings of words that wouldn't be guessed easily. I have very few hard-and-fast rules, except "don't use the names/birth dates of your children, pets, spouse, etc". Keep the words impersonal. The xkcd is better than my plan, but back then, code-breaking was more a function of informed guessing and "human engineering". Still, you don't want the curious to log in as a supervisor or administrator and find out how much everybody makes, look at personnel records, etc. That alone can be very destructive in an office atmosphere.
 
Last edited:
  • #16
In any case, before you start using strings of words, you really ought to make sure your system actually considers every character significant. Some systems, for example, only use the first 8 characters, making XKCD's advice rather terrible.
 
  • #17
During my tenure then, we bought all the equipment from a recently failed ophthalmic practice, and the bank that foreclosed (the doctor went bankrupt from malpractice suits) wanted help breaking the master password on the practice-management software so they could try to recover some of the outstanding receivables. I looked in the most obvious places for jotted passwords, then told the bank reps to strip all certificates, etc, off the walls and bring them to me while I continued to hunt.

I had no luck searching the main office, but one of the certificates had the doctor's birth-date on it. I formatted it in the MMDDYY numeric format, and punched that date in in reverse order. BINGO! The bank reps got pretty fired up, and asked what else I needed. I told them to go to Staples and buy a new printer ribbon for that dot-matrix printer, and a couple of cases of tractor-feed paper. I got them started, showed them how to pause printing and re-start and they got a complete paper record of the practice's receivables.
 
Last edited:
  • #18
Does anyone know if the 10-20 most common passwords has changed much over the last 10 years? I would think password1 is probably still one of the most common right?

http://en.wikipedia.org/wiki/Password

I like the one about hotmail banning the pw 123456 heh.
 
  • #19
Hurkyl said:
It's not all that hard to memorize a random sequence of 8 characters if you spend a few minutes practicing it. :-p
What if you have three? At my last job (Gov), one to get the desktop operating system to boot, one to get onto the LAN then one to get onto the Gov network. Oh and one for their mail. And every 30 days we were prompted to change them. What made it bad was prompts were not in sync.
 
  • #20
dlgoff said:
What if you have three? At my last job (Gov), one to get the desktop operating system to boot, one to get onto the LAN then one to get onto the Gov network. Oh and one for their mail. And every 30 days we were prompted to change them. What made it bad was prompts were not in sync.

No joke:
  • Local admin login - laptop
  • Local admin login - desktop
  • Network login
  • Mail login
  • Remote support login (different for every site)
  • VPN login
  • My company's FTP site login
  • Siemens' FTP login
  • Siemens' SiePro login
  • Simotion controller FTP login (different for every site)
  • Simotion IT diagnostics login (different for every site)
  • Legacy modem connection login (different for every site)
  • TestTrack Pro login
  • VSS login

Yup; those are real. I keep my passwords in my KeyPass program on my phone in an encrypted file to which the password is "password."
 

Related to The truth about password strength

1. What is the importance of having a strong password?

A strong password is crucial for protecting your personal information and accounts from being hacked or stolen. It acts as a barrier against unauthorized access and ensures the security and privacy of your data.

2. How do I create a strong password?

A strong password should be at least 12 characters long and include a combination of uppercase and lowercase letters, numbers, and special characters. Avoid using easily guessable information like your name, birthdate, or common words. Consider using a password manager to generate and store strong passwords for you.

3. Is it necessary to change my password regularly?

While it's always a good idea to regularly update your passwords, it's not necessary to do so unless you suspect a security breach or have used a weak password. Instead, focus on creating a strong and unique password for each account and enabling two-factor authentication for added security.

4. Can I use the same password for multiple accounts?

No, it's not recommended to use the same password for multiple accounts. If one account gets hacked, all your other accounts using the same password will also be vulnerable. It's best to use unique passwords for each account to ensure maximum security.

5. Are there any other methods for securing my accounts besides using a strong password?

Yes, there are other methods for securing your accounts, such as using two-factor authentication, regularly updating your software and devices, and being cautious about clicking on suspicious links or emails. It's also essential to use different passwords for different accounts and regularly monitor your account activity for any suspicious behavior.

Similar threads

  • General Discussion
2
Replies
37
Views
7K
  • General Discussion
Replies
4
Views
735
Replies
49
Views
3K
  • Special and General Relativity
Replies
11
Views
1K
  • Electrical Engineering
Replies
3
Views
871
  • High Energy, Nuclear, Particle Physics
2
Replies
48
Views
19K
  • General Discussion
Replies
15
Views
3K
  • Quantum Interpretations and Foundations
4
Replies
138
Views
5K
  • Engineering and Comp Sci Homework Help
Replies
4
Views
2K
  • Biology and Medical
Replies
2
Views
2K
Back
Top