View Single Post
Old 04-21-2009, 02:18 PM  
raymor
Confirmed User
 
Join Date: Oct 2002
Posts: 3,745
Letting users choose their own passwords sucks because so many choose "password"
for their password, or something equally as easy to guess. A great many will choose
a dictionary word or a variation on a dictionary word, such as adding a single digit to
the end, so that's easy for the bad guys to guess.

Typical auto generated passwords suck because "Ad%O$#908sD^!" is very hard to
remember and easy to mistype. We found another approach which doesn't suck, and
we made a free online tool for anyone who wants to use it. We generate passwords which
LOOK like English words, so they are very easy to type and aren't too hard to remember.
They are NOT actually words, though, so they won't be in the cracker's dictionary.
Examples are frucspin and relitemer . The free tool to generate these can be found at:
http://www.bettercgi.com/strongbox/passgen/
__________________
For historical display only. This information is not current:
support@bettercgi.com ICQ 7208627
Strongbox - The next generation in site security
Throttlebox - The next generation in bandwidth control
Clonebox - Backup and disaster recovery on steroids
raymor is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote