Complexify - a jQuery Plugin to ACCURATELY Gauge Password Complexity
danpalmer.me
danpalmer.me
Password complexity doesn't prevent phishing, password complexity doesn't prevent social engineering which are in my experience the 2 biggest issues. Password complexity only really prevents brute forcing, but any system that allows you to hammer it with 100, 1000 or 10000 requests isn't going to be secure anyway. It also goes some way to preventing a password being cracked if the hash is stolen, but that shouldn't be an issue if proper security practices are followed. The only other possibility is that complex passwords can't be read over the shoulder or memorised, if someone sees "p4ssw0rd" it's easy to remember, "P$()\£\(\FDDFA" isn't.
The only real value in complex passwords that I can see is that it makes users think "my password is only 10% secure? I must try harder at security!" but do many even think that? I pay no attention to the complexity meters sites have...
So what am I missing? The way I see it the only real security is a password manager with unique passwords for every account. Surely encouraging that is better than wasting time telling a user if you think their password is secure or not?
As for your other point, using a password manager is good, but not always practical. I have an algorithm I use so that I know all of my passwords, but they are different.
Sites that require you to have a number in it, or a capital letter, or something like that are doing the wrong thing and promoting poor passwords. People think "if I add a number on the end its far more secure" when it isn't. This provides a far more accurate measure so that sites can enforce a minimum complexity which promotes good passwords.
If a sites database is hacked then you can assume their entire site is compromised, in which case whether or not they find out your password is moot because if you use real security and every site has a unique password you risk nothing if they do crack it. If you use the same password for every site cracking is the least of your worries, what if a website is breached and the login system is replaced with a system that stores your password? What if you're phished? What if your computer is stolen and someone just checks your saved passwords? No matter how complex a password is if it's used on multiple websites it's insecure.
However, I am in the small minority and we have to face the fact that most people use one or only a handful of passwords, and these people have a very poor idea of the criteria for a good password, mainly because so many sites have poor guidelines, and poor policies (like max 16 chars, no punctuation, etc).
Password complexity (when done right) DOES makes it more difficult to:
-brute force passwords -crack hashes -perform rainbow table attacks -do password sweeps, e.g. do one password guess on every known user name (effectively avoiding account lockout) -do 'one off' guesses
It is not perfect alone, but it is one very important component of every secure and reliable application.
My "issue" (if you can call it that) is if you say to a user signing up to your website "Your password is 50% secure!" they'll mistakenly assume that means they're safe and can throw out all other security practices. It doesn't matter how complex their password is a password is never secure when humans are involved, a password can be considered secure enough if it's unique to a website but once a password is being used on multiple websites it doesn't matter how complex it is, all it takes is for one site to be breached and it's a worthless password.
Instead of telling users that if their password meets some arbitrary requirements that it's suddenly more secure than another password that has 1 less character we should tell them that they need to assume their password can be stolen and if it is using unique passwords per website will protect them.
Passwords aren't either "secure" or "insecure" based on the password itself, they're secure until someone else knows it. If your password becomes insecure (either through phishing or brute forcing) you need to be ready to limit the damage, if every website you use has the same password (no matter how complex it is) and your password becomes insecure you have a huge problem, if you use a unique password per-website you're safe from most damage.
If you have an account on 100 websites it's better to have an "easy" password (eg: "2809911234" (my birth date followed by 1234)) different on each website than it is to have 1 password on every website that is super complex (eg: "£(U&(FDJHDIFHJDJHF&DF&^SDF&^S^&*").
Password security should work under the assumption that someone DOES know your password or WILL know your password and you should be limiting the problem. People sign up to websites all the time that they have no idea how secure they are, I administrate a website with 1.3 million users, I could be a scary russian hacker that is just stealing their details to hack their Paypal accounts and empty their banks, but if they had unique passwords everywhere that would not be an issue. It doesn't matter how complex a password is, the moment you input it into a form on a website it becomes insecure.
To tl:dr; my waffle and address your main point:
> just because password complexity doesn't mitigate some of your carefully constructed scenarios, doesn't mean that it's useless.
You're correct, password complexity isn't useless but it isn't important enough to warrant being the only thing users are told. Password complexity is a small part of having good online security; making it the focus of security by using it in forms is misleading to users. Anecdotally I know someone (supposedly smart) who berated me for having a password that was only 10 characters long because a website said a 10 character password can be hacked in 3 days, he didn't understand that the 3 days is how long it would take a computer to compute my password, not that someone could "target" me and have my password on their computer in 3 days. Even smart people don't have a clue about security and password complexity on forms just misleads them further.
Passwords are secure until someone else knows it, they're not secure based on how complex they are. A password that is 16 characters is only more "secure" than a 10 character password if you live in a vacuum where the only issue is brute forcing (or similar computational attacks).
"8 characters with a number" - the criteria many normal users consider a good password, is just not good enough any more in this ago of $2.50 an hour for an EC2 instance with a few graphics cards.
This is my answer. Passwords are judged on their complexity properly rather than a naïve interpretation of complexity.
If you do implement it somewhere, let me know where. Also fork and contribute if you want.
As for your password scoring 56%, that's not too bad. But adding more characters has more of an effect that adding a wider range of characters. This is how it should be.