Educause Security Discussion mailing list archives
Re: Password entropy
From: Alan Amesbury <amesbury () OITSEC UMN EDU>
Date: Tue, 25 Jul 2006 13:07:55 -0500
Roger Safian wrote:
BTW - you can download Passphrase_Length_and_Complexity_Considerations.xls from <http://www.shiloh.k12.il.us/tech/feast2006/Scripting/JasonFossenScripts/Day6--Scripting/> If the sheet is incorrect, I'd like to know.
Attached is a spreadsheet (MSexcel, sorry) I put together for a manager a number of years ago. It's limited to eight character passwords (produced with the original Unix crypt() in mind), but possibly useful. Anyway, you can change the lighter colored cells. It's **VERY** rough, but it was useful enough to get my point across when I needed it. I keep intending to put together a more polished version that can handle longer password lengths, but--well, lately I've been spending all my free time reading this thread. ;-) For an additional informal analysis of password strengths, see http://www1.umn.edu/oit/security/passwordattackdiscussion.html I've included a couple of system benchmarks useful for the "rate of testing" cell in the attached spreadsheet. Note that this can also be used to help gauge the effectiveness of a brute-force SSH attack (which is another form of brute-force password attack, albeit one with a really slow password/second rate). -- Alan Amesbury University of Minnesota
Attachment:
password_cracking_worksheet.xls
Description:
Current thread:
- Re: Password entropy, (continued)
- Re: Password entropy Roger Safian (Jul 24)
- Re: Password entropy Graham Toal (Jul 24)
- Re: Password entropy Valdis Kletnieks (Jul 24)
- Re: Password entropy Basgen, Brian (Jul 24)
- Re: Password entropy Roger Safian (Jul 24)
- Re: Password entropy Harold Winshel (Jul 24)
- Re: Password entropy Jimmy Kuo (Jul 24)
- Re: Password entropy Valdis Kletnieks (Jul 24)
- Re: Password entropy Roger Safian (Jul 25)
- Re: Password entropy Basgen, Brian (Jul 25)
- Re: Password entropy Alan Amesbury (Jul 25)
- Re: Password entropy Valdis Kletnieks (Jul 25)