Most corporate users are bombarded with guidelines and regulations on how to set good passwords. Users are forced to remember rules they don’t want to, leading to password fatigue. Administrators are given the sense that passwords are secure and users feel the same way if they’re following the rules. People know that a password has to be 8 characters, but they really don’t know why – here are some surefire ways to be certain you (and your users) are picking weak passwords, despite length and complexity requirements. 1 Make It Up Yourself – Most users are going to come up with a ‘familiar base’, then add simple numbers and symbols (1 and !) to make their passwords compliant. Make good[…]

Password strength meters are all over the Net. These tools are designed to determine how long, random, and complex a given password is.

In general, I think they make good indications about passwords to guide people. It’s just that most people type in their dictionary word and tack on a number or two to get a ‘strong’ password.

See how PasswordMeter.com rates these 2 passwords (the second one randomly generated using 63 available ASCII characters):

  • ‘Computer1’ – 56% = “Good” password rating.
  • ‘buty1{’ – 34% = “Weak” password rating.

Try it, a couple of random passwords and I got 28-70% ratings using just 6 characters. I know this is all in the algorithms used at each stage – so what’s a user to do?

However, it’s probably not what you think… They’re not using PKI, or SecurID, or those cruddy images we’ve mentioned before. No, this time they are using Entrust IdentityGuard which is… one time pads? From the Dark Reading article Users receive Bingo-like cards with thousands of passwords on them. Since their entries are determined by when they access Treasury Direct, the passwords constantly change and make it tough for hackers to crack. Another plus: It cost only 25 cents for each card, and the cards were available in Braille for the sight-impaired. Wow, now we’re really moving into the 21st century. Another card to carry around in my wallet, which I can use for… oh, just one thing. And it’s electronic,[…]