[Tutorial] How NOT To Store Your Users' Passwords
#9

Quote:
Originally Posted by Y_Less
View Post
This actually isn’t a good idea. The trend in passwords is towards things that are hard for people to remember, but really easy for computers to guess, since they literally don’t care about the difference between S and $. Meanwhile people will try and meet the requirements in the simplest way possible, with something like p4S$word - and they all think they’re really clever because they used @ instead of a, which is not clever at all and all the good crackers know about literally every replacement scheme. A MUCH better scheme (known as “correct horse battery staple”) is to have the user select four random words (there are services for this, but they tend to use a reduced word set - just flick through a dictionary, or get a word from the back of a shampoo bottle or something):

glossy lock pillar stinky


VASTLY easier to remember, and VASTLY harder to crack.

See the XKCD comic that introduced it:

https://www.xkcd.com/936/
And what do you think about KeePass password generator actually? Is that going to be in your opinion not safe as well, because "all the good crackers" are going to know the basics of character generator algorithm behind it?
Reply


Messages In This Thread
How NOT To Store Your Users' Passwords - by Sasino97 - 27.06.2018, 13:11
Re: How NOT To Store Your Users' Passwords - by Robin96 - 27.06.2018, 13:28
Re: How NOT To Store Your Users' Passwords - by RogueDrifter - 27.06.2018, 13:33
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 27.06.2018, 14:30
Re: How NOT To Store Your Users' Passwords - by Uproar - 27.06.2018, 14:42
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 27.06.2018, 15:31
Re: How NOT To Store Your Users' Passwords - by jlalt - 27.06.2018, 15:39
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 27.06.2018, 15:58
Re: How NOT To Store Your Users' Passwords - by Riddick94 - 27.06.2018, 17:22
Re: How NOT To Store Your Users' Passwords - by Freaksken - 27.06.2018, 17:55
Re: How NOT To Store Your Users' Passwords - by Mobtiesgangsa - 27.06.2018, 22:36
Re: How NOT To Store Your Users' Passwords - by Garr - 27.06.2018, 23:59
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 28.06.2018, 07:27
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 28.06.2018, 09:09
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 28.06.2018, 09:24
Re: How NOT To Store Your Users' Passwords - by Y_Less - 28.06.2018, 09:27
Re: How NOT To Store Your Users' Passwords - by Sasino97 - 28.06.2018, 09:47
Re: How NOT To Store Your Users' Passwords - by Riddick94 - 28.06.2018, 10:07
Re: How NOT To Store Your Users' Passwords - by [HLF]Southclaw - 28.06.2018, 10:13
Re: How NOT To Store Your Users' Passwords - by Y_Less - 28.06.2018, 13:37

Forum Jump:


Users browsing this thread: 1 Guest(s)