Calculating Password Policy Strength vs. Cracking

InfoWorld’s Roger Grimes offers a spreadsheet-based calculator in which you can key in your current password policy and see how your organization’s passwords might hold up against the number of guesses an attacker can make in a given minute. As an example, Grimes assumes an eight-character password, with complexity enabled, a 94-symbol character set, and 90 days between password changes. Such a policy, typical for many organizations, would require attackers to make only 65 guesses per minute to break — not at all hard to accomplish, Grimes writes.


