Linked by snydeq on Fri 22nd May 2009 18:15 UTC
Privacy, Security, Encryption InfoWorld's Roger Grimes offers a spreadsheet-based calculator in which you can key in your current password policy and see how your organization's passwords might hold up against the number of guesses an attacker can make in a given minute. As an example, Grimes assumes an eight-character password, with complexity enabled, a 94-symbol character set, and 90 days between password changes. Such a policy, typical for many organizations, would require attackers to make only 65 guesses per minute to break -- not at all hard to accomplish, Grimes writes.
Permalink for comment 365081
To read all comments associated with this story, please click here.
Lockout policy
by stestagg on Sat 23rd May 2009 00:38 UTC
stestagg
Member since:
2006-06-03

Any sane system doesn't allow 65 guesses a day, let alone per minute.