Your Pa$$Word Doesn't Matter
techcommunity.microsoft.com
techcommunity.microsoft.com
Content: your password matters very much
What?? My takeaway is that your password matters quite a lot, you need to use a password manager to generate strong, unique passwords, and turn on MFA everywhere you can. Not “your passwords don’t matter”
> Your password doesn’t matter except for password spray (avoid the top guessed passwords with a dictionary checker of some kind) or brute force (use more than 8 characters, or use a password manager if you are really nervous). That’s not to say your password isn’t terrible. It’s definitely terrible, given the likelihood that it gets guessed, intercepted, phished, or re-used.
At the bottom of the article.
But yeah, your password choices very much matter and those choices can foil {credential stuffing, password spray, brute force}, which is admitted but downplayed in the article.
Considering that most people reading the article will be security-minded, a far better title would have been "Your Users' Password Choices Often Don't Matter".
although one that cycled passwords regularly would presumably do the trick.
About all this article shows that is the only "complexity" test that matters is that a password shouldn't be in the Top X most used passwords, and X may be as low as 10 (much less the thousands you can easily check with Pwned Passwords) if you are attempting (distributed) password spray detection in your login systems, MFA, etc.
Though the takeaway in the article is that you really only need to check Top X and Top X may be as low as 10 assuming other mitigations are in place.
Are there any notable exceptions, where attackers don't have the db, but can probe pretty quickly?
One day WebAuthn might be usable for all the things. I want that to come soon but it is not here yet.