Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Passphrase strength, is this right?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Stealth »
« Sudo for Windows  
AuthorAll Replies

dantz

join:2005-05-09
Honolulu, HI
reply to Jack Morgan
Re: Passphrase strength, is this right?

Sounds like you are considering a variation of the Diceware Passphrase approach. You should check out this page:

»world.std.com/~reinhold/diceware.html


Anon users



...... 1500 words means ~ 2^~10 bit of randomess, thus a 5 word from 'that dict' means ~ 2^53 bit of security

Given 2^~72 bit of security (RSA200 challenge) CAN be broken within 5 MONTHS with a array of computers... a 2^55 bit of security CAN BE BROKEN within 1/2 MIN!!!

BUT it is NOT THAT BAD compared to COMMON 8 chars of Upper/Lower Case + Numbers ONLY to log in to your WEBMAIL... it has 2^~45 bit of security only...

Just imagine...

mysec
Premium
join:2005-11-29

reply to dantz

I couldn't get this link to open.
I'll try again later...

-rich

dantz

join:2005-05-09
Honolulu, HI
·Hawaiian Telcom

said by mysec See Profile :


I couldn't get this link to open.
I'll try again later...

-rich
The link is still good. You can also type in »diceware.com and it will take you there.

Diceware uses a 7,776 word dictionary. Ordinary dice are used as a random-number generator in order to select each word that will be included in the passphrase. In my opinion, it's a highly effective system as well as a very clever solution to the problem of users failing to select high-quality passwords/passphrases. I especially like the use of dice as a random-number generator, as opposed to the pseudo-random numbers that most computers provide.

The advantage of using the Diceware method is that you can quickly and easily create strong passwords that can actually be remembered. However, this advantage quickly begins to fade if you need to remember more than one or two passwords, as human memory has its limits. (Maybe we need to add more RAM!)

I use KeePass to generate and store all of my passwords, and these are applied using copy/paste operations so I don't have to remember them or type them in, nor could I. (%kjC7UqOIBb'=&dc/w0,i*3Pwa}43 can barely be typed correctly on the first try, let alone remembered). All I have to know is my master password and the location of the keyfile. I suppose Diceware would be a good way to generate my master password, but I'm already using another system for that.
Forums » Up and Running » Security » SecurityStealth »
« Sudo for Windows  


Wednesday, 02-Dec 00:14:11 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [133] Comcast Releasing Promised Usage Meter
· [68] Baltimore To Ban Lazy Cable Installs
· [56] Broadband Killed The Game Console
· [50] Latest Consumer Reports Survey Not Kind To AT&T
· [49] Rogers Unveils The ISP Dream Model
· [40] Rural Carriers Quickly Embracing Fiber
· [36] ACTA: Global Three Strikes
· [35] Charter Exits Chapter 11
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [25] Vivendi Agrees, Comcast/NBC Deal Soon
Most people now reading
· Am I the only one that loves to work in IT? [No, I Will Not Fix Your #@$!! Computer]
· Download speeds very slow. [AT&T West]
· Windows 7 boot manager editing questions [Microsoft Help]
· Ooma changing features [VOIP Tech Chat]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Why Criminals (Hackers) Must Not Be Rewarded [Security]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Maximizing Rogue DPS for ToC/ToGC (3.x) [World of Warcraft]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]