MCD ProductsReloading EverythingRepackboxMidSouth Shooters Supply
RotoMetals2Inline FabricationTitan ReloadingLee Precision

Page 2 of 2 FirstFirst 12
Results 21 to 34 of 34

Thread: Password Strength

  1. #21
    Boolit Buddy gsdelong's Avatar
    Join Date
    Sep 2010
    Location
    Southern Indiana
    Posts
    360
    I does not appear to look at dictionary attacks. By the way the above site looks like a great way to build a huge dictionary of passwords. Also evaluate P@$$w0rd probably in the first 50 guesses of any 15 year old with IT knowledge.

  2. #22
    Boolit Bub
    Join Date
    Mar 2011
    Location
    New Mexico
    Posts
    68
    I'm impressed. Mine came in as:
    GRC's Interactive Brute Force Password “Search Space” Calculator
    (NOTHING you do here ever leaves your browser. What happens here, stays here.)

    3 Uppercase
    6 Lowercase
    2 Digits
    1 Symbol
    12 Characters



    Enter and edit your test passwords in the field above while viewing the analysis below.
    Brute Force Search Space Analysis:
    Search Space Depth (Alphabet): 26+26+10+33 = 95
    Search Space Length (Characters): 12 characters
    Exact Search Space Size (Count):
    (count of all possible passwords
    with this alphabet size and up
    to this password's length)
    546,108,
    599,233,516,079,517,120
    Search Space Size (as a power of 10): 5.46 x 1023
    Time Required to Exhaustively Search this Password's Space:
    Online Attack Scenario:
    (Assuming one thousand guesses per second)
    1.74 hundred billion centuries
    Offline Fast Attack Scenario:
    (Assuming one hundred billion guesses per second)
    1.74 thousand centuries
    Massive Cracking Array Scenario:
    (Assuming one hundred trillion guesses per second)
    1.74 centuries
    Note that typical attacks will be online password guessing
    limited to, at most, a few hundred guesses per second.

  3. #23
    Boolit Buddy
    Join Date
    Sep 2008
    Posts
    174
    Hmmm seems a few of mine were a bit weak, easy to crack, so have just updated them. I typed in similar types of passwords and not ones in use then used the information to strengthen mine. Ones for important places are longer for obvious reasons.

    Here is the result:-

    Brute Force Search Space Analysis:
    Search Space Depth (Alphabet): 26+26+10+33 = 95
    Search Space Length (Characters): 19 characters
    Exact Search Space Size (Count):
    (count of all possible passwords
    with this alphabet size and up
    to this password's length)
    38,
    136,800,256,227,897,272,
    064,940,472,866,626,495
    Search Space Size (as a power of 10): 3.81 x 1037
    Time Required to Exhaustively Search this Password's Space:
    Online Attack Scenario:
    (Assuming one thousand guesses per second)
    12.13 trillion trillion centuries
    Offline Fast Attack Scenario:
    (Assuming one hundred billion guesses per second)
    1.21 hundred thousand trillion centuries
    Massive Cracking Array Scenario:
    (Assuming one hundred trillion guesses per second)
    1.21 hundred trillion centuries


    Hmmmt hat should about do methinks
    Last edited by Brithunter; 07-09-2014 at 05:19 AM.

  4. #24
    Boolit Buddy Cornbread's Avatar
    Join Date
    Apr 2014
    Location
    NW Montana
    Posts
    460
    Quote Originally Posted by gsdelong View Post
    I does not appear to look at dictionary attacks. By the way the above site looks like a great way to build a huge dictionary of passwords. Also evaluate P@$$w0rd probably in the first 50 guesses of any 15 year old with IT knowledge.
    Using a simple sentence that is 14 characters or longer like I suggested will defeat dictionary attacks as well so long as you don't use something like "ThisIsMyPassword".
    Neither a borrower nor a lender be;
    For loan oft loses both itself and friend,
    And borrowing dulls the edge of husbandry.
    This above all: to thine ownself be true

  5. #25
    Boolit Master

    alamogunr's Avatar
    Join Date
    Mar 2005
    Location
    Tennessee
    Posts
    4,526
    I just found this thread. Very interesting. While I don't choose easy passwords, I do use the same one for any site that is of no consequence if hacked. Such as Cast Boolits. I try to use unique passwords for critical sites(bank accounts, credit card accounts, brokerage accounts, etc.) and change them occasionally.

    I haven't gone to the referenced site yet but will and will probably change many of my passwords.

    I am curious if anyone has a comment about my passwords for sites than have no financial consequences.
    John
    W.TN

  6. #26
    Boolit Grand Master

    dragon813gt's Avatar
    Join Date
    Feb 2012
    Location
    Somewhere
    Posts
    9,989
    Quote Originally Posted by alamogunr View Post
    I am curious if anyone has a comment about my passwords for sites than have no financial consequences.
    I do the same. They all aren't the same but I do use a few of them repeatedly. This is one of the few forums where my password is unique due to how and when I signed up.

  7. #27
    Boolit Master

    alamogunr's Avatar
    Join Date
    Mar 2005
    Location
    Tennessee
    Posts
    4,526
    I just changed the passwords on several sites that would have financial impact if hacked. One of them limited the length to 12 characters. Another was not case sensitive. The first had no impact on security and the second(comparison below) appeared to me to be significant.

    Search Space Depth (Alphabet): 26+10+33 = 69
    Search Space Length (Characters): 10 characters
    Exact Search Space Size (Count):
    (count of all possible passwords
    with this alphabet size and up
    to this password's length)
    2,
    482,167,502,723,212,150
    Search Space Size (as a power of 10): 2.48 x 1018
    Time Required to Exhaustively Search this Password's Space:
    Online Attack Scenario:
    (Assuming one thousand guesses per second)
    7.89 hundred thousand centuries
    Offline Fast Attack Scenario:
    (Assuming one hundred billion guesses per second)
    9.47 months
    Massive Cracking Array Scenario:
    (Assuming one hundred trillion guesses per second)
    6.89 hours


    Search Space Depth (Alphabet): 26+26+10+33 = 95
    Search Space Length (Characters): 10 characters
    Exact Search Space Size (Count):
    (count of all possible passwords
    with this alphabet size and up
    to this password's length)
    60,
    510,648,114,517,017,120
    Search Space Size (as a power of 10): 6.05 x 1019
    Time Required to Exhaustively Search this Password's Space:
    Online Attack Scenario:
    (Assuming one thousand guesses per second)
    19.24 million centuries
    Offline Fast Attack Scenario:
    (Assuming one hundred billion guesses per second)
    19.24 years
    Massive Cracking Array Scenario:
    (Assuming one hundred trillion guesses per second)
    1.00 weeks


    On the site that didn't recognize alpha case differences, I didn't change the password. I probably will at some later time. Also my passwords are not memorable. I have to write them down. It is somewhat inconvenient if I need a password while away from home, but I accept that. An intruder might possible find my list but he would have to stay in the house much longer than would be comfortable,
    John
    W.TN

  8. #28
    Boolit Master



    Join Date
    Jul 2009
    Location
    Where Pennsylvania, Delaware, and Maryland join.
    Posts
    2,195
    I like this one:

    Tea42AndILoveYou!

    Brute Force Search Space Analysis:
    Search Space Depth (Alphabet): 26+26+10+33 = 95
    Search Space Length (Characters): 17 characters
    Exact Search Space Size (Count):
    (count of all possible passwords
    with this alphabet size and up
    to this password's length)
    4,225,684,238,917,218,
    534,300,824,429,126,495
    Search Space Size (as a power of 10): 4.23 x 1033
    Time Required to Exhaustively Search this Password's Space:
    Online Attack Scenario:
    (Assuming one thousand guesses per second)
    1.34 billion trillion centuries
    Offline Fast Attack Scenario:
    (Assuming one hundred billion guesses per second)
    13.44 trillion centuries
    Massive Cracking Array Scenario:
    (Assuming one hundred trillion guesses per second)
    13.44 billion centuries
    Blacksmith

    S. G. G. = Sons of the Greatest Generation. Too old to run, too proud to hide; we will stand our ground and take as many as we can with us!

  9. #29
    Banned
    Join Date
    May 2013
    Location
    Idaho
    Posts
    579
    I should be in purdy fair shape.

    Brute Force Search Space Analysis:
    Search Space Depth (Alphabet): 26+10+33 = 69
    Search Space Length (Characters): 11 characters
    Exact Search Space Size (Count):
    (count of all possible passwords
    with this alphabet size and up
    to this password's length)
    171,
    269,557,687,901,638,419
    Search Space Size (as a power of 10): 1.71 x 1020
    Time Required to Exhaustively Search this Password's Space:
    Online Attack Scenario:
    (Assuming one thousand guesses per second)
    54.46 million centuries
    Offline Fast Attack Scenario:
    (Assuming one hundred billion guesses per second)
    54.46 years
    Massive Cracking Array Scenario:
    (Assuming one hundred trillion guesses per second)
    2.83 weeks

  10. #30
    Boolit Master chuckbuster's Avatar
    Join Date
    Aug 2009
    Location
    Michigan
    Posts
    592
    Seven Characters and a Capital works for me

    DocSleepyGrumpyBashfulHappyDopeySneezyLansing


    Kevin
    Why don't you knock it off with them negative waves? Why don't you dig how beautiful it is out here? Why don't you say something righteous and hopeful for a change? (Sgt. Oddball, KELLY'S HEROES)
    __________________________________________________ __________________________________________________ _____________________________
    my feedback thread
    http://castboolits.gunloads.com/show...raight-shooter

  11. #31
    Boolit Master

    alamogunr's Avatar
    Join Date
    Mar 2005
    Location
    Tennessee
    Posts
    4,526
    I would hope that no one is posting actual passwords that they intend to use.
    John
    W.TN

  12. #32
    Boolit Bub
    Join Date
    Dec 2013
    Posts
    36
    For those who have a lot of passwords, I recommend LastPass. It keeps track of all of your passwords. I don't even know my passwords as they are randomly generated by LastPass. The Chrome extension auto fills the passwords. There is also an app for iOS and Android.

    By default it generates passwords that are 12 characters and contain uppercase, lowercase, and numbers. It says that a randomly generated password would take 1.04bil centuries to crack using the online fast method. Good enough for me.

    I keep a backup encrypted spreadsheet just in case something ever happens to LastPass.

  13. #33
    Boolit Mold
    Join Date
    May 2014
    Posts
    11
    Quote Originally Posted by attrapereves View Post
    For those who have a lot of passwords, I recommend LastPass. It keeps track of all of your passwords. I don't even know my passwords as they are randomly generated by LastPass. The Chrome extension auto fills the passwords. There is also an app for iOS and Android.

    By default it generates passwords that are 12 characters and contain uppercase, lowercase, and numbers. It says that a randomly generated password would take 1.04bil centuries to crack using the online fast method. Good enough for me.

    I keep a backup encrypted spreadsheet just in case something ever happens to LastPass.
    I love this app. Makes work so much easier where the sites require a 9 character password.

  14. #34
    Boolit Master


    David2011's Avatar
    Join Date
    Jan 2007
    Location
    Baytown Texas
    Posts
    4,123
    As the website says, there are two types of password strength. One is the complexity and the other is the dictionary strength. By using a string of characters that is not a word you increase the dictionary strength considerably. The string need not be very long. Something like zpKx or the a letter from the name of some family members with a mix of upper and lower case would seriously increase the dictionary strength.

    You can test your password on the OP's link by entering a different combination of characters that has the same quantity of upper case, lower case, punctuation and numeric characters as your actual password. The results will be the same in the test.

    David
    Sometimes life taps you on the shoulder and reminds you it's a one way street. Jim Morris

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Abbreviations used in Reloading

BP Bronze Point IMR Improved Military Rifle PTD Pointed
BR Bench Rest M Magnum RN Round Nose
BT Boat Tail PL Power-Lokt SP Soft Point
C Compressed Charge PR Primer SPCL Soft Point "Core-Lokt"
HP Hollow Point PSPCL Pointed Soft Point "Core Lokt" C.O.L. Cartridge Overall Length
PSP Pointed Soft Point Spz Spitzer Point SBT Spitzer Boat Tail
LRN Lead Round Nose LWC Lead Wad Cutter LSWC Lead Semi Wad Cutter
GC Gas Check