Unit 4-Question 2

How to create a strong password – Password strength

What is a strong password?

Strong passwords are the ones that are difficult to guess and often require a mix of uppercase, lowercase, numbers and symbols. Strongest passwords require a minimum of 16 characters, however, a password between 8 and 16 characters is said to provide a good level of security.

The required quality of the password depends on how well the password system is to limit the number of guesses of a member’s password, whether from someone who knows the member well, or from a computer that is probing. millions of possibilities. A good system has a limit to the number of logins from 1 IP address, or adds a captra authentication step if it is wrong more than n times…

To set a strong password:

Examples of strong passwords are:

A strong password is one that is sufficiently long, random, or otherwise contrived only by the person who chooses it, that it would take longer to guess it than it would take a cracker. password lock ready to spend to guess it. The time to be deemed too long will vary depending on the attacker, the attacker’s resources, the ease of access to tryable passwords, and the value of the password to the attacker. . A student password isn’t worth a few seconds for a computer to guess, while a password that manages access to a major bank’s electronic money transfer system can be worth weeks or even weeks. months to guess.

It would be a mistake to use the passwords listed below: they are publicly available, so they are weak. All comments on password strength assume that they are unknown and unwritten. While similar passwords, or based on the same principles, will be strong enough, assuming you don’t read them.

t3wahSetyeT4 – case sensitive and alternating digits

4pRte!ai@3 –case sensitive, alternating digits, punctuation, and a “special” character

MoOoOfIn245679-case sensitive, alternating digits

Convert_100£ to Euros!- phrases can be long, easy to remember, and contain extended symbols for increased strength, but some weaker password hashing methods may depend on frequency analysis

1382465304H – a string of numbers ending with a character

Tp4tci2s4U2g! – A blend of characters with different case letters, numbers, and punctuation. It’s easy to remember because it’s the beginning of the word “The password for this computer is too strong for you to guess!”

5:*35pm&8/30 – Phone time and date with two random “special” characters

EPOcsoRYG5%4pp@.djr – uses multiple factors including capitalization and special characters

What is a weak password?

A weak password is a short, common password, a system-provided default, or something that can be guessed quickly by performing a brute force attack using a subset of all possible passwords, such as dictionary words, proper names, username-based words, or common variations of those words. Passwords that can be easily guessed based on knowledge of the user, such as date of birth and pet name, are also considered weak.

Examples of weak passwords:

admin— too easy
1234—too predictable

abc123—too predictable

minh—common proper name

password—easily guessed, very often used

p@$$//0rd — leet and plain-character cipher both pre-programmed in jailbreak tools

rover—common pet name, also a dictionary word

12/3/75—date, may be important to the individual

December12—It’s very common to use a mandatory password change date

nbusr123—probably a username, and if so, extremely predictable

asdf—sequence of characters in various keyboards

qwerty—a string of characters that are contiguous in many keyboards

aaaa—repeated, predictable characters

