in reply to Re: Demonstrate Weakness of "Standard Format" Passwords
in thread Demonstrate Weakness of "Standard Format" Passwords

As a matter of fact any constraint on the composition of passwords will dramatically reduce the keyspace and is therefore a bad idea.

I strongly disagree with this assertion for one particular constraint... Disallow "words". I.e. dictionary words, names, pop culture words, jargon, etc. That one's a must and crack (or your favorite replacement) with a good set of dictionaries should be run regularly to make sure it is enforced. There are some other good restraints: disallowing dates, phone numbers, and bible verse references for instance.

-sauoq
"My two cents aren't worth a dime.";
  • Comment on Re^2: Demonstrate Weakness of "Standard Format" Passwords