Page 1 of 1

Password strength checking site

PostPosted: Thu Apr 26, 2012 12:23 pm
by pfarber
http://howsecureismypassword.net/

It does not send you password anywhere, the javascript is all on your PC. That was my first concern, too.

My passwords ranged from 3 hours to 467 years to crack.

While its an entertaining site, most logins will lock your account from further attempts after 3 to 5 incorrect passwords. But some places like ebay may give many more guesses. I have not had an ebay account lock on me ever.... and I've made at least 10 attempts at times.

Industry standard guidelines:
A minimum password length of 12 to 14 characters if permitted (7 is typically considered the MINIMUM - PDF)
Generating passwords randomly where feasible
Avoiding passwords based on repetition, dictionary words, letter or number sequences, usernames, relative or pet names, romantic links (current or past), or biographical information (e.g., ID numbers, ancestors' names or dates).
Including numbers, and symbols in passwords if allowed by the system
If the system recognizes case as significant, using capital and lower-case letters
Avoiding using the same password for multiple sites or purposes