RE: How secure is your password? 09-05-2017, 08:01 PM
#6
(09-05-2017, 04:14 PM)mothered Wrote: 50 chars Is an overkill.
I could create an 8 character length password that's just as secure , whereby It contains upper case, lower case, numbers, special characters (not consistent with that of "malicious" chars used In attacks such as SQLi). It must also meet complexity requirements, whereby no 2 chars of the same type are allowed In the same sequence (no two upper case, lower case, special chars etc).
And then go one step further, whereby nothing sequential to the keypad Is allowed. Whether It be your cell phone or qwerty keyboard- horizontal, diagonal, vertical or anything following a logical order Is not permitted.
Also, depending "where" I utilize my password, the strength of the username Is of equal Importance. For example, on my forum (back-end login), the username Is dedicated to myself only and no other external source so the strength/complexity of the username Is just as Important as It's counterpart. A lot of people focus on passwords alone. When solely dedicated to the user, both forms of authentication (user:pass) must meet the same complexity.
It might be overkill with over 50 chars, but that is the password that protects all my logins, thereby making it the most important.
(09-05-2017, 05:23 PM)Skryptec Wrote:(09-05-2017, 08:10 AM)Sikom Wrote: I guess I also could disclose that my password has special characters, numbers, big and small letters, and has a length of above 50 chars.
The thing here is, long passwords are not always the most secure passwords. Short and complex passwords are more secure in my opinion.
Long passwords are not always the most secure no, but if you have a long password with the main rules followed (Small letter, Big letter, Number, and Special) it will certainly be more secure with a long password vs a small one, if we look at bruteforcing.
What I think we can agree on, is that normal computers will not be able to bruteforce the password in a good amount of time. (I do not know about quantum computers) but that is not viable for most people to get.
(09-05-2017, 05:24 PM)DarkMuse Wrote: I mean it's really not difficult to make a strong password guys.
Stop using the fucking websites who will generate them for you, -- why the fuck would you trust them?
Think of a memorable phrase include punctuation and capitalization. Now take every first letter and include the punctuation in the password.
For example,
It takes 2 to tango, but 3 for a threesome.
Becomes
It2tt,b3fat.
LOOK AT THAT A SECURE PASSWORD.
Obviously using popular phrases is stupid, use something that you'll remember.
Bruteforce wise it would be better to do the long one vs the small one. I am not quite sure about dictionary attacks. But I think it would be hard to crack that sentence with a dictionary attack.
(This post was last modified: 09-05-2017, 09:39 PM by Sikom.)









![[+]](https://sinister.li/images/modern/collapse_collapsed.png)