abcdefg123456! abcdefg!123456 abcdefg1!23456 = 5 seconds
a!bcdefg123456 = 1 week
Moving the ! supposedly increases the difficulty several orders of magnitude.
21–30 of 60 posts
abcdefg123456! abcdefg!123456 abcdefg1!23456 = 5 seconds
a!bcdefg123456 = 1 week
Moving the ! supposedly increases the difficulty several orders of magnitude.
This is about as rough as an approximation as you can get. For example, if your password contains dictionary words that aren't in their top passwords, it drastically overestimates the the difficulty of cracking it.
Type `"".hackability` in the console to see the code.
Yes, lets teach users to type their passwords into "checking" tools. Great. edit: on the plus side, "CONGRATULATIONS! It would take about 2546476408336 years to crack your password." (I typed in a password that was roughly equivalent to a very secure and memorable one I memorised but have never found a use for. It's a correcthorsebatterystaple style password.)
In general, including the spaces is a better idea, because collisions.
On the other hand, if you're using MD5 CRYPT, they're assuming $100,000 worth of ASICs. If you're using PBKDF2-SHA256 with standard "login credentials" parameters (100 ms of CPU time), it's $14,000,000 worth of ASICs. bcrypt, $100,000,000. scrypt, $4,000,000,000. And if you're using scrypt with typical file-encryption parameters (5 s of CPU time), $15,000,000,000,000 worth of ASICs.
Moral of the story: Whether your password is strong enough depends as much on how it's stored as it does on the password itself.
This doesn't seem supper reliable abcdefg123456! abcdefg!123456 abcdefg1!23456 = 5 seconds a!bcdefg123456 = 1 week Moving the ! supposedly increases the difficulty several orders of magnitude.
Your first password, they interpret as aa! Your second, a!a Your third, a1!23456 Your fourth, a!bcdefga
There are clearly some problems here. "bacon giraffe coffee paper head": 2 weeks "coffee banana tourist nose": 15368 years Or even worse: "i like salt": 18 years "i like pepper": 9 hours
> "i like pepper": 9 hours
Well that's clearly because salted passwords are more secure.
There are clearly some problems here. "bacon giraffe coffee paper head": 2 weeks "coffee banana tourist nose": 15368 years Or even worse: "i like salt": 18 years "i like pepper": 9 hours
"salt tastes ok": 324658 years
"intel password sweepstakes": 8441109 years
"dictionary attack": 390 years
password1 = 0 seconds
password12 = 0.0002 seconds
password123 = 0.0027 seconds
password1234 = 0.0272 seconds
Conclusion - password1234 is 100 times safer than password12. Thanks Intel! Changing my passwords now!
And while public key authentication may seem difficult to implement server-side by doing such a thing you will never risk a database password leak again.