<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Dictionary for Password Strength Testing in Webmasters and Developers</title>
<link>http://www.dslreports.com/forum/r13103789</link>
<description></description>
<language>en</language>
<pubDate>Wed, 25 Nov 2009 03:47:21 EDT</pubDate>
<lastBuildDate>Wed, 25 Nov 2009 03:47:21 EDT</lastBuildDate>

<item>
<title>Re: Dictionary for Password Strength Testing</title>
<link>http://www.dslreports.com/forum/remark,13111411</link>
<description><![CDATA[<A HREF="/useremail/u/429566"><b>Jason Levine</b></A> : I encourage passphrases too.  Not only are they hard to guess, but they're pretty easy to remember.  "We're off to see the wizard!" is a 28 character password/phrase that's pretty secure and easier to remember than "1ri&br#a#ho9thiucoe!l27ieslu"<br><SMALL>--<br>-Jason Levine<BR><A HREF="http://www.jasons-toolbox.com/">http://www.jasons-toolbox.com/</A><BR><A HREF="http://www.PCQandA.com/">http://www.PCQandA.com/</A><BR><A HREF="http://www.urateit.com/">http://www.urateit.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13111411</guid>
<pubDate>Thu, 07 Apr 2005 13:20:18 EDT</pubDate>
</item>

<item>
<title>Re: Dictionary for Password Strength Testing</title>
<link>http://www.dslreports.com/forum/remark,13110942</link>
<description><![CDATA[<A HREF="/useremail/u/557058"><b>DA OH</b></A> : We use pass phrases here, but only the initials from them.  For example:  road runner is very fast becomes rrivf.  For added security, we also add special characters, so the final password becomes: !rrivf!<br><SMALL>--<br>"Victory goes to the player who makes the next-to-last mistake."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13110942</guid>
<pubDate>Thu, 07 Apr 2005 12:07:25 EDT</pubDate>
</item>

<item>
<title>Re: Dictionary for Password Strength Testing</title>
<link>http://www.dslreports.com/forum/remark,13110112</link>
<description><![CDATA[<A HREF="/useremail/u/281766"><b>Mospaw</b></A> : Our IT manager is encouraging the use of "pass phrases" instead of passwords. Something like "Mospaw is a genius." or even "Four score and seven years ago" to type in. Nice and long, and very difficult to guess. You could even have "Four score and 7 years ago" to make it harder to guess, but still very easy to remember.<br><br>The only issue is that some applications/web sites may limit password length, so the longer phrases may be problematic. I would think that 80 characters would handle just about all reasonable pass phrases.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13110112</guid>
<pubDate>Thu, 07 Apr 2005 10:14:51 EDT</pubDate>
</item>

<item>
<title>Re: Dictionary for Password Strength Testing</title>
<link>http://www.dslreports.com/forum/remark,13109395</link>
<description><![CDATA[<A HREF="/useremail/u/886011"><b>big greg</b></A> : <div class="bquote"><SMALL>said by  Mospaw <A HREF="/useremail/u/281766"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><BR><BR>Lots of words here: &raquo;<A HREF="http://www.itasoftware.com/careers/WORD.LST" >www.itasoftware.com/careers/WORD.LST</A><br><br>You should be able to save that file and run a query on it. If you need help writing one, let me know. <br> </DIV>Excellent link!  Thanks!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13109395</guid>
<pubDate>Thu, 07 Apr 2005 07:43:03 EDT</pubDate>
</item>

<item>
<title>Re: Dictionary for Password Strength Testing</title>
<link>http://www.dslreports.com/forum/remark,13106002</link>
<description><![CDATA[<A HREF="/useremail/u/758549"><b>fiqqq</b></A> : be careful not to throw out passwords that meet all of the other expectations like dog!#Murphy, !# being his age but with shift pressed. as these are strong passwords and better than users having to remember 435A93k*m or the likes.<br><SMALL>--<br><A HREF="http://www.placidness.com">placidness.com</A>: my site.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13106002</guid>
<pubDate>Wed, 06 Apr 2005 20:16:20 EDT</pubDate>
</item>

<item>
<title>Re: Dictionary for Password Strength Testing</title>
<link>http://www.dslreports.com/forum/remark,13105240</link>
<description><![CDATA[<A HREF="/useremail/u/557058"><b>DA OH</b></A> :  <BLOCKQUOTE><SMALL>said by  Overdrive <A HREF="/useremail/u/400554"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><HR><div class="bquote">that's a lot of words...<br> <HR></BLOCKQUOTE><br><br>173,528 to be exact. :-)<br><SMALL>--<br>"Victory goes to the player who makes the next-to-last mistake."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13105240</guid>
<pubDate>Wed, 06 Apr 2005 18:30:58 EDT</pubDate>
</item>

<item>
<title>Re: Dictionary for Password Strength Testing</title>
<link>http://www.dslreports.com/forum/remark,13104241</link>
<description><![CDATA[<A HREF="/useremail/u/400554"><b>Overdrive</b></A> : <div class="bquote"><SMALL>said by  Mospaw <A HREF="/useremail/u/281766"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>:</SMALL><br><br>Lots of words here: &raquo;<A HREF="http://www.itasoftware.com/careers/WORD.LST" >www.itasoftware.com/careers/WORD.LST</A><br><br>You should be able to save that file and run a query on it. If you need help writing one, let me know. <br> </DIV>that's a lot of words...<br><SMALL>--<br><A HREF="http://www.sanzone.net">Need a Web Developer?</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13104241</guid>
<pubDate>Wed, 06 Apr 2005 16:30:40 EDT</pubDate>
</item>

<item>
<title>Re: Dictionary for Password Strength Testing</title>
<link>http://www.dslreports.com/forum/remark,13104092</link>
<description><![CDATA[<A HREF="/useremail/u/429566"><b>Jason Levine</b></A> : Thanks.  This should help a lot!  :-)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13104092</guid>
<pubDate>Wed, 06 Apr 2005 16:14:49 EDT</pubDate>
</item>

<item>
<title>Re: Dictionary for Password Strength Testing</title>
<link>http://www.dslreports.com/forum/remark,13103866</link>
<description><![CDATA[<A HREF="/useremail/u/281766"><b>Mospaw</b></A> : Lots of words here: &raquo;<A HREF="http://www.itasoftware.com/careers/WORD.LST" >www.itasoftware.com/careers/WORD.LST</A><br><br>You should be able to save that file and run a query on it. If you need help writing one, let me know. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13103866</guid>
<pubDate>Wed, 06 Apr 2005 15:51:47 EDT</pubDate>
</item>

<item>
<title>Dictionary for Password Strength Testing</title>
<link>http://www.dslreports.com/forum/remark,13103789</link>
<description><![CDATA[<A HREF="/useremail/u/429566"><b>Jason Levine</b></A> : I saw a link to a Password Strength tester (&raquo;<A HREF="http://www.securitystats.com/tools/password.php" >www.securitystats.com/tools/password.php</A>) in another thread and thought that it would be a great tool for my users.  However, I don't want them submitting their passwords across the Internet and some of the suggestions (upper case) don't apply in our situation (we have case insensitive passwords).  Therefore, I'm looking at building it myself.<br><br>So far, it looks like they check 5 criteria:<br><br>1.  Is the password in the dictionary?<br>2.  Is the password 8 characters or more in length?<br>3.  Does the password include special symbols?<br>4.  Does the password contain numbers?<br>5.  Does the password contain mixed case?<br><br>I'd wind up replacing that last one with:<br><br>5.  Does the password match the user's username?<br><br>Numbers 2-5 are easy to implement.  However, #1 requires that I have a database of common words to query against.  Does anyone know of any free/low-cost sources for this that I could use to populate a SQL Server database?<br><SMALL>--<br>-Jason Levine<BR><A HREF="http://www.jasons-toolbox.com/">http://www.jasons-toolbox.com/</A><BR><A HREF="http://www.PCQandA.com/">http://www.PCQandA.com/</A><BR><A HREF="http://www.urateit.com/">http://www.urateit.com/</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,13103789</guid>
<pubDate>Wed, 06 Apr 2005 15:43:10 EDT</pubDate>
</item>

</channel>
</rss>
