{"id":97,"date":"2008-08-22T08:57:13","date_gmt":"2008-08-22T13:57:13","guid":{"rendered":"http:\/\/richard.rathe.org\/?p=97"},"modified":"2010-04-03T18:04:53","modified_gmt":"2010-04-03T22:04:53","slug":"better-passwords","status":"publish","type":"post","link":"https:\/\/redmangrove.org\/rathe.org\/richard\/2008\/better-passwords","title":{"rendered":"Better Passwords?"},"content":{"rendered":"<p><a href=\"http:\/\/richard.rathe.org\/wp-content\/uploads\/2008\/11\/password_entropy_graph.jpg\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-99 alignright\" title=\"Password Entropy Graph\" src=\"http:\/\/richard.rathe.org\/wp-content\/uploads\/2008\/11\/password_entropy_graph-300x238.jpg\" alt=\"Password Entropy Graph\" width=\"300\" height=\"238\" srcset=\"https:\/\/redmangrove.org\/rathe.org\/richard\/wp-content\/uploads\/2008\/11\/password_entropy_graph-300x238.jpg 300w, https:\/\/redmangrove.org\/rathe.org\/richard\/wp-content\/uploads\/2008\/11\/password_entropy_graph.jpg 578w\" sizes=\"auto, (max-width: 300px) 85vw, 300px\" \/><\/a>The best passwords are completely random\u2014strong but almost impossible to remember. <a href=\"http:\/\/csrc.nist.gov\/archive\/pki-twg\/y2004\/Presentations\/twg-04-04.pdf\">This report<\/a> from the <a href=\"http:\/\/csrc.nist.gov\/\">National Institute of Standards and Technology<\/a> (NIST) suggests a better solution\u2014<strong>long pass phrases<\/strong>.<\/p>\n<p><strong>Entropy<\/strong> is a measure of password strength. The more entropy a password has, the harder it is to crack. Many systems enforce dictionary and composition rules (numbers, mixed case, punctuation)  on short (less than ten character) passwords. <a href=\"http:\/\/richard.rathe.org\/wp-content\/uploads\/2008\/11\/password_entropy_graph.jpg\" target=\"_blank\">This graph<\/a> on page 23 of the <a href=\"http:\/\/csrc.nist.gov\/archive\/pki-twg\/y2004\/Presentations\/twg-04-04.pdf\">NIST report<\/a> shows that <strong>dictionary rules do not improve longer passwords<\/strong>, and the boost from composition rules is fairly small. A simple twelve character <strong>pass phrase<\/strong> (a-z plus spaces) is as strong as an eight character rule-based password, but can be <strong>much easier to type and remember<\/strong>. Throw in one digit and you&#8217;ve got a very strong credential indeed! I&#8217;ve written a <a href=\"http:\/\/medinfo.ufl.edu\/omi\/docs\/practical_passwords\/\" target=\"_blank\">quick three step approach<\/a> for the UF campus system (which unfortunately does not allow spaces).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The best passwords are completely random\u2014strong but almost impossible to remember. This report from the National Institute of Standards and Technology (NIST) suggests a better solution\u2014long pass phrases. Entropy is a measure of password strength. The more entropy a password has, the harder it is to crack. Many systems enforce dictionary and composition rules (numbers, &hellip; <a href=\"https:\/\/redmangrove.org\/rathe.org\/richard\/2008\/better-passwords\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Better Passwords?&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[18],"tags":[],"class_list":["post-97","post","type-post","status-publish","format-standard","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/redmangrove.org\/rathe.org\/richard\/wp-json\/wp\/v2\/posts\/97","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/redmangrove.org\/rathe.org\/richard\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/redmangrove.org\/rathe.org\/richard\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/redmangrove.org\/rathe.org\/richard\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/redmangrove.org\/rathe.org\/richard\/wp-json\/wp\/v2\/comments?post=97"}],"version-history":[{"count":11,"href":"https:\/\/redmangrove.org\/rathe.org\/richard\/wp-json\/wp\/v2\/posts\/97\/revisions"}],"predecessor-version":[{"id":103,"href":"https:\/\/redmangrove.org\/rathe.org\/richard\/wp-json\/wp\/v2\/posts\/97\/revisions\/103"}],"wp:attachment":[{"href":"https:\/\/redmangrove.org\/rathe.org\/richard\/wp-json\/wp\/v2\/media?parent=97"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/redmangrove.org\/rathe.org\/richard\/wp-json\/wp\/v2\/categories?post=97"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/redmangrove.org\/rathe.org\/richard\/wp-json\/wp\/v2\/tags?post=97"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}