To LUGNET HomepageTo LUGNET News HomepageTo LUGNET Guide Homepage
 Help on Searching
 
Post new message to lugnet.admin.generalOpen lugnet.admin.general in your NNTP NewsreaderTo LUGNET News Traffic PageSign In (Members)
 Administrative / General / 5736
5735  |  5737
Subject: 
Re: Automated password appraisal (Re: New feature: Article rating)
Newsgroups: 
lugnet.admin.general
Date: 
Thu, 30 Mar 2000 18:08:57 GMT
Highlighted: 
(details)
Viewed: 
3789 times
  
In lugnet.admin.general, Frank Filz writes:
I have a suggestion, you may want to test substitute things like "!" as
a substitute for "l" or "i".

You mean, change from checking !->i to checking both !->i and !->l ?  (It
does currently check !->i -- did that not work for you in some instance?)


Have you thought about vowels being dropped and K/c substitutions.

Good idea!


I have a password which I would consider a worthless password the way you
are scoring them which depends on these two transformations. I'll be
happy to e-mail it to Todd directly if he wants to look at it and
consider how to detect

Lemme see about the above suggestions and then you can try it again later
without having to email it...


(of course that may start to become hard to ever
find a password, for things like this, the weakness may depend on
context [i.e. what is the account being used for, or what are the
person's interests]).

Well, in the end, the checker is doing more of a "randomness evaluation"
than anything else.  Memorability and practicality aside, the best passwords
are those which are close to being truly random and far away from being
generateable by looping or cracking algorithms.  So the trick is to find
a password which is still memorable and typeable while being randomish
enough.

--Todd



Message has 2 Replies:
  Re: Automated password appraisal (Re: New feature: Article rating)
 
(...) Ah, checked again, it didn't detect "7!" as a mapping for "li", but did detect "7i" as "li". It did reject both passwords though, but it had a lot fewer problems with the "7!" version, and the level changed from "worthless" to "weak". (...) (25 years ago, 30-Mar-00, to lugnet.admin.general)  
  Re: Automated password appraisal (Re: New feature: Article rating)
 
(...) Hmmm...not sure how to go about doing this... The way the checker achieves its speed is by looking up all substrings in its dictionary rather than passing every single diciontionary word over all substrings (which could take hours). So, for (...) (25 years ago, 30-Mar-00, to lugnet.admin.general) ! 

Message is in Reply To:
  Re: Automated password appraisal (Re: New feature: Article rating)
 
I have a suggestion, you may want to test substitute things like "!" as a substitute for "l" or "i". Have you thought about vowels being dropped and K/c substitutions. I have a password which I would consider a worthless password the way you are (...) (25 years ago, 30-Mar-00, to lugnet.admin.general)  

309 Messages in This Thread:
(Inline display suppressed due to large size. Click Dots below to view.)
Entire Thread on One Page:
Nested:  All | Brief | Compact | Dots
Linear:  All | Brief | Compact

This Message and its Replies on One Page:
Nested:  All | Brief | Compact | Dots
Linear:  All | Brief | Compact
    

Custom Search

©2005 LUGNET. All rights reserved. - hosted by steinbruch.info GbR