To LUGNET HomepageTo LUGNET News HomepageTo LUGNET Guide Homepage
 Help on Searching
 
Post new message to lugnet.admin.generalOpen lugnet.admin.general in your NNTP NewsreaderTo LUGNET News Traffic PageSign In (Members)
 Administrative / General / 5741
5740  |  5742
Subject: 
Re: Automated password appraisal (Re: New feature: Article rating)
Newsgroups: 
lugnet.admin.general
Date: 
Thu, 30 Mar 2000 18:42:19 GMT
Highlighted: 
(details)
Viewed: 
3490 times
  
In lugnet.admin.general, Todd Lehman writes:
In lugnet.admin.general, Todd Lehman writes:
[...]
I'll put this password thingy up on a webpage for people to try out, maybe
later tonight.  If we can all agree that it does a good job of weeding out
bad passwords, then I'll put it into place for where you can actually change
your own password.

Inconsistent results.  It quite happily failed obvious stuff like "James1" or
"Galliard" or "June15", but also missed some glaring ones.

For example, it failed my Social Insurance number, but only because it was all
from 1 keyboard row.  It passed (albiet grudgingly) a version with some
numbers straight substituted for alpha equivalents.

It also thought "06/15/72" (my birthdate) was "Great" -->*Very Bad*

It doesn't seem to account for keyboard shifting. "Galliard" (from my e-mail)
failed, but "Tqoo8q4e", a straight keyboard shift up, passed.  Other shifts
(from my name, for example) only failed for other reasons.

It doesn't check QWERTY vs Dvorak translations, for example "Ham.o1" is
"James1" in Qwerty on a Dvorak keyboard, and it got a "great".  Some other
obvious/common words failed the translation.

Also, just as an aside, it generates "mild risk" for the weirest things!

James
http://www.shades-of-night.com/lego/
I'm getting paid for this --> alladvantage.com
Sign up via me, the reference $$ go to fund Lugnet.



Message has 1 Reply:
  Re: Automated password appraisal (Re: New feature: Article rating)
 
(...) Try again now. :) (...) It doesn't check for up/down/left/right keyboard shifting, no. (...) It doesn't check for cross-keyboard translations either, no. If I can get my hands on more keyboard xy tables, maybe I can check for these too. (...) (...) (24 years ago, 30-Mar-00, to lugnet.admin.general)  

Message is in Reply To:
  Re: Automated password appraisal (Re: New feature: Article rating)
 
(...) OK, here it is: (URL) summary: Type in a password and it tells you "pass" or "fail". First important question: Are there any bad passwords which this fails to reject? (If it rejects a seemingly good password, that's not necessarily a problem. (...) (24 years ago, 30-Mar-00, to lugnet.admin.general) !! 

309 Messages in This Thread:
(Inline display suppressed due to large size. Click Dots below to view.)
Entire Thread on One Page:
Nested:  All | Brief | Compact | Dots
Linear:  All | Brief | Compact

This Message and its Replies on One Page:
Nested:  All | Brief | Compact | Dots
Linear:  All | Brief | Compact
    

Custom Search

©2005 LUGNET. All rights reserved. - hosted by steinbruch.info GbR