Skip to main content

Posts

Showing posts from September, 2014

Reality of Password Policy and its Effectiveness

The last P@$$w0rd! that you were bragging about in your mind has a very different reality . Stronger Password Policy that forces users to  use symbols, uppercase , numbers and lowercase characters is losing its very purpose to make it more time consuming for an adversary to crack it. According to a research done in Carnegie Mellon University,  most user choose (!,@,#,$) to comply with so called "stronger password policy" to use a symbol which make it easier for attacker to guess the password  and defeat the very purpose . The point that i want to make is :- Please don't choose a password that first come to your mind !