How secure is my password
howsecureismypassword.net
howsecureismypassword.net
Also:
momof3g8kids
It would take a desktop PC about
37 years
to crack your password
But radix had that password (and thousands of others) in an hour[1][1] http://arstechnica.com/security/2013/05/how-crackers-make-mi...
'badpassword' 10 days
'bad1password' 37 years
'bad password' 546 years
'bad 1password' 333 thousand years
'bad password 1' 18 million years
'bad 123password' a billion years
As with all password checkers, there are problems here.If you want a password checker, this one is still the best I've seen: http://dl.dropboxusercontent.com/u/209/zxcvbn/test/index.htm... (it correctly identifies all my above examples as terrible passwords)
But password security is much more about using bcrypt or scrypt (in case someone gets your database) and having timeouts and lockouts on password entry (to prevent brute-forcing through public channels).
That's what I did - generate a new password using my usual method.
Apparently "it would take a desktop PC about 13 duovigintillion years to crack your password" - is that long enough?
First of all it doesn't take into account GPU cracking techniques - in fact it uses an average desktop PC as the processing power gauge (completely ignoring that password crackers would be running on highly powerful systems bespokely configured systems),
Next it doesn't take into account modern dictionary attacks - sometimes people will have a seemingly secure password but it's actually a common term and thus included in password dictionaries.
And to top it all off, there's no details about how long it would take against different encryption cyphers (the best cyphers are designed to be computationally expensive - but sadly a lot of sites are still using SHA128/256, or worse yet, MD5).
It's rare that I'm this rude about other peoples projects, but that site is total garbage. In fact it's worse than garbage because it deludes people into thinking their passwords are secure when often they're not. It's alarming how quick hackers can rattle off password attempts these days - to quote a recent Ars article[1] "Using a commodity computer with a single AMD Radeon 7970 graphics card, it took him 20 hours to crack 14,734 of the hashes, a 90-percent success rate." and that's an extremely low spec machine compared to most.
[1] http://arstechnica.com/security/2013/05/how-crackers-make-mi...
If the cracker was trying to brute force a password, then they would have to try every available character in every valid position. Unless I'm misunderstanding something, and n-length password would take a similar amount of time to guess as any other n-length password with the same restrictions. The cracker doesn't know going into it that I only have letters in my password, so he has to use any valid character.
Perhaps a more useful system would be one that would let websites enter their password restrictions and tell them how secure their users' password can be with those restrictions.
Typically hackers will run through quicker combinations to pick off the low hanging fruit. It doesn't matter if they can't crack a few hundred 15 char characters with extended ANSI characters as by that point they'll already have tens of thousands of passwords from others who's passwords contained less entropy.
I think we should be educating people on using different passwords for services rather than convincing them to use very long, complex passwords.
What I typically do is give "important" services unique, random passwords (bank, personal email, work email; things that can do damage), and use one of a set of passwords for everything else. If one password gets found, then maybe only my Reddit, Skype and a few forum accounts are compromised. This has the advantage that I use the unique password frequently enough to memorize them, and non-unique passwords are used in a few places which results in them also being used enough that they are memorized.
My name is bob smith from California USA and I am trying to login to: xxx