Passwords

Dan Bernstein brnstnd at kramden.acf.nyu.edu
Fri Apr 12 14:14:48 AEST 1991


In article <26518 at adm.brl.mil> JRAMSDEN%wl7.prime.com at relay.cs.net writes:
> *But* if you then add a couple of numbers or a  symbol,  to  make  say
> "Sch23wartzkopf"  it  gets  converted immediately from being guessable
> (at a pinch) to impossible.

Someone might search for passwords where each character is 70% lowercase
letter with Shannon frequencies, 10% uppercase letter, 15% digits 23457
(surely you know these are the most common?), 5% other digits. He'd get
that password after, say, a hundred billion encryptions---around two
months on a small Sun cluster. These are back-of-the-envelope estimates,
but I certainly wouldn't say that password was impossible to guess.

---Dan



More information about the Comp.unix.wizards mailing list