Good presentation on Password Strength

I came across an interesting article on nist.gov which goes into some details on the strength of various passwords in bits of entropy per character, amongst other things. One point that interested me was that in most of the projections the marginal gain in entropy decreased as the password length increased, so going from say 4 characters to 5 characters would gain you more entropy than going from 29 to 30.

Of course that assumes you're not using totally random strings for passwords, but then who does that (apart from people with extremely good memories of course....!)

About this Entry

This page contains a single entry by Rory2 published on March 22, 2004 8:31 PM.

Analogies in the Security World was the previous entry in this blog.

Root Cause Analysis in penetration testing is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Pages

Powered by Movable Type 4.37

About this Entry

This page contains a single entry by Rory2 published on March 22, 2004 8:31 PM.

Analogies in the Security World was the previous entry in this blog.

Root Cause Analysis in penetration testing is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.