Happy New Year: your password sucks

The tale, as retold by an IT support mate of mine over one too many beers recently, of the user who swore her password was ******** as that’s what the login screen said is about as likely to be true as any other IT support shaggy dog story, it did get me to thinking about the true cost of password insecurity.

At the very least it serves to illustrate how just a few characters can make all the difference when it comes to password security, and that size and complexity do have a direct impact upon the resources required to break through the basic defences. So, and please excuse the very broad brush strokes I am using to paint this particular picture, a password of ‘dumbo’ would take about a second for a brute force application to crack using the processing power of an average PC. Changing that to ‘dumbo123′ would extend the time required to approximately 3 days, and ‘dumbo12345678′ jumps into half a million years territory. Start throwing in non-alphanumeric stuff such as pound signs and exclamation marks and things get really ridiculous: dumbo12345678£ = 19 million years, dumbo12345678£! = 71 billion years and dumbo12345678£!£ = about 3 trillion years according to the online password security calculator at howsecureismypassword for example.

