I Know What Your Password Was Last Summer
labs.lares.com
I Know What Your Password Was Last Summer
1–10 of 103 posts
Re: I Know What Your Password Was Last Summer
#2Re: I Know What Your Password Was Last Summer
#3I crack alot of hashes, people pick really bad passwords. Ive had tools running on raspberry pi's crack client passwords in meetings with them... in minutes...
Re: I Know What Your Password Was Last Summer
#4Re: I Know What Your Password Was Last Summer
#5Re: I Know What Your Password Was Last Summer
#6Re: I Know What Your Password Was Last Summer
#7You can easily remember 4 to 6 random words. You really will be surprised how quickly it is to memorize and type after a day or two. Mixing them up with what separator (if any) that you use, and if you number/special character substitute that adds dozens of possible permutations on a single password. And just using 4-letter words (over 100,000 in the English language) leads to a 100 quintillion possible passwords without any separator or character substitutions.
The next requirement should be no arbitrary changes to passwords. End users should be able to pick a strong 16 character password (based on uniqueness and the other password strength tools they recommend in the article) and only change it if they forgot it or a breach of their account is suspected.
Re: I Know What Your Password Was Last Summer
#8I always wonder why employers don't just set passwords for their users and only give them the option to randomize them. Seems like an ideal solution, if using passwords is a requirement.
Re: I Know What Your Password Was Last Summer
#9I crack alot of hashes, people pick really bad passwords. Ive had tools running on raspberry pi's crack client passwords in meetings with them... in minutes...
Re: I Know What Your Password Was Last Summer
#10Not mentioned in the article, but I bet seasonal/time-related passwords are due to password rotation policies. I work for a company too slow or stupid to have understood how counterproductive such policy is, and all my passwords are an update of the former. Because we humans cannot remember multiple strong passwords.