Educause Security Discussion mailing list archives

Re: Password length and complexity


From: "Irish, Adrian L" <Adrian.Irish () MSO UMT EDU>
Date: Fri, 31 May 2013 17:46:57 +0000

This is not scholarly, but certainly technical, and eye opening (at least
for me): 

 

Anatomy of a hack: How crackers ransack passwords like "qeadzcwrsfxv1331"

http://arstechnica.com/security/2013/05/how-crackers-make-minced-meat-out-of
-your-passwords/

 

Adrian

 

Adrian Irish

IT Security Officer

The University of Montana

SS 102

Missoula, MT 59812

(406) 243-6375

 

 <mailto:adrian.irish () umontana edu> adrian.irish () umontana edu

 

From: The EDUCAUSE Security Constituent Group Listserv
[mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Eric Weakland
Sent: Friday, May 31, 2013 11:08 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Password length and complexity

 

Greetings, 

Do any of you have any links handy to scholarly/technical articles that have
recommendations or strategies on choosing appropriate password length and
complexity requirements?  We're working on extending out password expiration
period significantly - let's say 1 year, and will be using things like
2-factor for extremely sensitive accounts, and I want to make sure we are
using a sound rationale/reasons for the length we choose - backed up by some
research. 

Anyone know of useful studies/research results that could help guide our
recommendations? 

Best, 


Eric Weakland, CISSP, CISM, CRISC
Director, Information Security
Office of Information Technology 
American University
eric at american.edu
202.885.2241

______________________________________
AU IT will never ask for your password via e-mail. 
Don't share your password with anyone!

Attachment: smime.p7s
Description:


Current thread: