I'd say about 50% of the people ended up with their current password on a post-it on their monitor or desk.
I'd say about 50% of the people ended up with their current password on a post-it on their monitor or desk.
I'd based on the available data that could have just as much security, without all the user hassle, if we just require long passwords, no other requirement. Can you see how much easier it is to just say, your password has to be 16 characters or longer. Just think of a passphrase. For instance: IWa1kmydogonSaturdays Easy to remember, and I would argue, though would want to try to provide some evidence, that this would be just as, if not more secure than 8 characters with ridiculous requirements.
... then I bet lots of users will choose passwords like "passwordpasswordpassword".
... with all due apologies to PIL.
I particularly liked the suggestion (elsewhere) to set passwords to a random combination of three dictionary words. It's hard to remember 7Gw$kW_ws, but I bet I could come up with a meaning for "dog shower flange".
With a password the key is always entropy. You can use all the smarts in the world to avoid the pre-computation attacks on your password... but never forget that brute force is not limited to character by character attack :)
In fact, just one word with a couple of numbers has the same effect.
Don't forget though, you are trusting this password to a site. If they are hacked, what then? Your 2K years turns into minutes or hours.
So assume they've got something lame like SHA-1 hashes, even on commodity hardware you're talking about 100,000 hashes a second. Now you're at 2.5 years. Setup a simple cluster or buy some CPU cards, and you easily get into the three month range.
Never Never NEVER use SHA-1 or MD5 for hashing your passwords, those algorithms are designed to be fast.
Anyway, the technique is called "Diceware", and you can pretty easily calculate how much entropy you're getting with it. (and assuming your attacker doesn't know you're using diceware, you're in even better shape.
"antelope" has 14,100,000 results
"antelope walrus" has 118,000 results
"antelope walrus biscotti" has 8,100 results
"antelope walrus biscotti eisenhower" has 1,690 results
"antelope walrus biscotti eisenhower lambchop" has 8 results!
Bonus if you can find a word combo which produces a single page of interesting sites, not word spam. Of course now that this comment is on the web, make that 9 results for "antelope walrus biscotti eisenhower lambchop".An average vocabulary has something like a million words in it, if you word count derivations. If you can expand that by a factor of five with easily memorable things like 1337-speak transformations, you can get above 80 bits with only 4 entities.
Another reason to grumble over SOX.
I do a lot of pen testing, and one of the easiest ways to get access to important things is figure out a way to go into the IT department under some premise. Passwords galore, the rest is just memory :)
(this is, sadly, only a slight exaggeration)