How Long Is Long Enough? Minimum Password Lengths by the World's Top Sites
troyhunt.com
troyhunt.com
https://blog.codinghorror.com/your-password-is-too-damn-shor...
The function is far from perfect as it was just the first implementation of that idea and never run in production. But I think as a base for a discussion it should be good enough.
function passwordComplexEnough($password){
$chars=0;
if(preg_match('/\p{Lu}+/', $password) === 1){ // letter upper case
$chars+=26;
}
if(preg_match('/\p{Ll}+/', $password) === 1){ // letter lower case
$chars+=26;
}
if(preg_match('/\p{Nd}+/', $password) === 1){ // decimal digit number
$chars+=10;
}
if(preg_match('/\p{S}+/', $password) === 1){ // symbol
// seems pessimistic but reasonable
$chars+=10;
}
$len = mb_strlen($password);
$complexity = pow($chars, $len);
// 62^8 (62 chars and length 8 as minimum complexity)
return ($complexity >= 218340105584896);
}
What do you think of this approach?I always think there are two ways to look at the password issue:
- It's the user's responsibility and you live it up to them not to use something stupidly weak if they value their accounts (at best you can hint them that the password is weak, but if they want to use "qwerty1234" you let them). This is the approach I expect from websites like HN, reddit, and the like.
- You want to protect the user and yourself, maybe because you're a website handling money transactions or you're a corporate website and you want to make sure every user has a decent password to access the company's resources etc... In this case the only satisfactory solution is to enforce strong 2FA and if that's really not an option then generate the password for the user. Otherwise they'll always figure out a way to reuse their passwords, generate a weak passwords that passes the predicate etc...
Because in the end, while I'm sure most people would agree that "oothe*Nah2phao0t" is a very strong password, what good is it if I reuse it across a large variety of websites? What about phishing and social engineering? I'm going to go out on a limb and guess that there probably are more Facebook account hacked because of password reuse and phishing websites than people blindly guessing passwords.
“Every single minimum password length is an even number!” You JUST mentioned that Wikipedia requires 1 character.
“There's no 5 or 7 or 9, just nice, round, symmetrically even numbers.” What do you mean by round numbers? Obviously not 10, 20, etc. So do you mean that the minimum lengths should have decimal points?
All jokes aside the article of course does make some good points
The worst password length I've seen recently is Skybet in the UK. It only allows digits 0-9 and has a maximum length of 5.
So nowadays, when I change my passwords, I have to make sure I don't hit the length limit, and after changing the password, confirm that it really changed to what I want to. In the few cases where it doesn't, I need to go through the entire dance to reset my password again...
https://www.reddit.com/r/WTF/comments/f96w7/amazon_security_...
I always thought the password should be hashed client-side. Supposedly that has some problems and it would still need to be hashed server-side as well.
So I have a proposal: client-side, hash the password. Can use any hash, although hash selection does limit the password security to its output. That hash is the new password sent over the wires to the server, that does proper password handling, but it is guaranteed a password of (say for SHA-256) 256 bits; if it receives a password that doesn't look like SHA-256 output it can automatically throw it out without even checking.
The client can then store the hash-input in his password manager, and it can be literally anything that can be thrown at the SHA hash. Is this feasible?
https://tools.ietf.org/html/rfc2617#section-3
The main issue with a "new" approach vis-a-vis basic etc, is that you need client support (will it work without js).
Then there's the question of what you're protecting against: if an attacker knows you accept a single round sha1-hashed pw, it's still easy to brute force through login, but it might require custom rainbow tables to account for the extra hash round.
But you'd be better off with a standard pw stretching / storage scheme for defeating off-line attacks.
So it is at most a RAM problem. Still, interesting talk point. Not very practical, but interesting.
[1]: https://www.helpnetsecurity.com/2013/09/17/too-long-password...
This is part of why it's funny to bring up. People are so used to focusing on bozos (who store plaintext) vs the initiated (who store salted hashes) that they are taken by surprise by other dimensions.
When I first read it as "PIN" I assumed it was some kind of quick password alternative for recognised devices and it would need a full password for unknown machines but nope, it's the whole password.
It horrifies me that at some point they thought, "A 4 digit pin isn't very secure, 6 should be enough!"
I've seen one instance where the password was "hashed" client side and the length thus didn't really matter, the implementation was lacking but they made an effort at least.
This is exactly why I treat sites that have password length restrictions with extreme caution, preferring to stay away altogether 99% of the time.
My bank use 4. And are numbers.
I wonder how many pornhub passwords are just ++++++
Not a "web site", but Microsoft does recommend a minimum of 7 characters for Windows 10 logins, and it's the default for domain policy, so that's pretty common.
https://docs.microsoft.com/en-us/windows/device-security/sec...
LAN Manager required a password up to 14 characters. It would then split the password into two 7 character parts and hash each independently. So there was no additional security offered by the algorithm for passwords over 7 characters. Today, LAN Manager passwords offer little protection as complete random tables are easily available.
Of course if the database is breached, then those protections go out the window and it comes down to the hashing algorithm used and its resistance to brute force attacks.
I think generally it will depend on the threat model of the site in question and what protections are in place.
(I'm not connected or affiliated with Dropbox or this project.)
It's fast, secure and open source.
Of course it isn’t as strong as a purely random passphrase but hopefully it would be strong enough and still better than choosing your own password
Another even number. Interesting.
Edit: typo.
Source: me, installing a bunch of High Sierra desktops late last year.
[1]https://addons.mozilla.org/en-US/firefox/addon/pwgen-reloade...
Sign up with only your email and you're logged in. If you need to log in later you can get an email link that validates you
Or maybe your service doesn't need a user account
But in the world of people that think their Mother's Maiden name is still relevant, smart user management is rare
Is there a reason this isn't more widespread?
https://blogs.dropbox.com/tech/2012/04/zxcvbn-realistic-pass...