leetify:
1eetify 13etify 133tify 1337ify 133y!fy ... leetif/
You've added about 100 new words for that one old word. Of course you can do this programmatically, so your actual dictionary stays the same size, but your search is still 100x or more longer.
silly, but at least it has length going for it
Or you use all the characters ?
cucumber of our discontent pot calls kettle soapy
Still relatively easy to remember but with less chance of being in some dictionary.
"apple" has 3 characters (2^3 = 8 variations) for easy leetspeak. "apples" has 2^4 = 16. "applestastegreat" has 2^12 = 4,096. Assuming you don't totally fubar your entropy in the underlying passphrase, you'll end up with something both memorable and infeasible to brute force.
Am I the only one? No. So the 'keyspace rules' don't accomplish anything, and may actually reduce the keyspace.
I'm guessing yes. If I were building a dictionary, I would add every password that's been dumped from sites like Gawker, etc. With hundreds of thousands of passwords floating around in the ether, you can quite quickly cover common leetifications. Also, it's trivially easy to leetify algorithmically, so padding a dictionary wouldn't be difficult. You'll run into space issues eventually, but you can easily split the dictionary over several machines.
The best solution for the user is to pick a fairly complex, long, and unique password. Server-side, assume your database will be compromised use something like bcrypt to make cracking it computationally expensive.
yes they are. well, actually, password cracking software (most used is Jack the Ripper) comes with a bunch of commandline tools that allow you to do substitutions and common variations to your password lists.
generally, when trying to crack a specific target, you start with a few "seed" password lists (common passwords, but also lists of target-specific jargon), and then apply the transformation tools on those to expand your lists.
say you'd want to crack accounts at an aviator forum, you'd include a list of airplane types and aviation jargon. then you'd apply the transformation tools, and you'll end up with boeing Boeing b0eing Bo3!ng, etc.
check this guy's blog, he writes about how it's (usually) done:
http://www.skullsecurity.org/blog/2010/the-ultimate-faceoff-... (analysis of leaked password lists) http://www.skullsecurity.org/blog/?s=ripper (describes Jack the Ripper in these articles)
Likewise, if dictionaries (and the permutation rules) lack a non-standard character, using that character will defeat the dictionary attack.
If you use a straight brute force then there's a trade off between the characters you use and the amount of time it'll take to exhaust a particular set of characters. It's only if the attacker is determined (and has usually exhausted alphanumeric character set brute forces) that you'll start to see other characters being added to the brute force. The great thing of course is that the attacker has to pretty much start from scratch with another set of permutations for each additional character.