M
Mike Schilling
Tom said:Which is absolutely not a good defence. "pa55w0rd" and "password1",
which are the kind of thing this rule usually engenders, are not a
lot more difficult to guess than "password" - it's a small
constant-factor increase in the amount of work a password cracker has
to do.
What would really make a difference is expanding password boxes to 200
characters (FSVO '200'), and telling people to use whole phrases. "I
used to use weensy passwords but now use humongous ones" is going to
take a very long time to guess.
At which point people, will, in self-defense, put their plaintext passwords
into disk files, so that they can cut and paste them.