Focus on Microsoft
Password complexity - improvement Aug 15 2007 06:14AM
dubaisans dubai (dubaisans gmail com) (5 replies)
RE: Password complexity - improvement Aug 16 2007 01:44PM
Jim Harrison (Jim isatools org)
Re: Password complexity - improvement Aug 15 2007 06:39PM
Ansgar -59cobalt- Wiechers (bugtraq planetcobalt net) (4 replies)
Re: Password complexity - improvement Aug 24 2007 09:53PM
Chris Barber (cmbarber gmail com)
You may have reduced the number of usable character combinations in a
fixed character password. But if I simply add the requirement of
having all 4 character types and leave the upper limit open, I have
just increased the keyspace astronomically.

Example
with password length fixed at 7 characters here are some numbers to look at:
Lower case only password has a keyspace of 8,031,810,176
Upper & lower case keyspace = 1,028,071,702,528
Upper, lower case & numbers = 3,521,614,606,208
Upper, lower, number & Special = 75,144,747,810,816

for a 10 Character password
Lower case only password has a keyspace of 141,167,095,653,376
Upper & lower case keyspace = 144,555,105,949,057,000
Upper, lower case & numbers = 839,299,365,868,340,000
Upper, lower, number & Special = 66,483,263,599,150,100,000

So, I do not agree that it is a negative impact on security.
Chris.

On 8/15/07, Ansgar -59cobalt- Wiechers <bugtraq (at) planetcobalt (dot) net [email concealed]> wrote:
> On 2007-08-15 dubaisans dubai wrote:
> > Is there a way to improve the password complexity requirements in
> > Windows 2000/2003 servers
> >
> > The default will enforce 3 of the following 4 properties - Uppercase,
> > smallercase, numbers, special-characters.
> >
> > Is there a way to enforce all 4 properties.
>
> Enforcing passwords that MUST consist of uppercase letters, lowercase
> letters, numbers AND special characters reduces the total number of
> possible passwords, which in consequence has a negative impact on your
> security.
>
> Regards
> Ansgar Wiechers
> --
> "All vulnerabilities deserve a public fear period prior to patches
> becoming available."
> --Jason Coombs on Bugtraq
>

[ reply ]
RE: Password complexity - improvement Aug 16 2007 09:00PM
Adrian Marsden (amarsden jvsdet org)
RE: Password complexity - improvement Aug 16 2007 04:32PM
Thor (Hammer of God) (thor hammerofgod com) (2 replies)
Re: Password complexity - improvement Aug 16 2007 09:09PM
Ansgar -59cobalt- Wiechers (bugtraq planetcobalt net)
RE: Password complexity - improvement Aug 16 2007 06:50PM
Devin Ganger (DevinG 3sharp com) (1 replies)
RE: Password complexity - improvement (correction) Aug 17 2007 09:29PM
James D. Stallard (james leafgrove com)
RE: Password complexity - improvement Aug 15 2007 10:53PM
Adrian Marsden (amarsden jvsdet org) (1 replies)
Re: Password complexity - improvement Aug 16 2007 03:39PM
Ansgar -59cobalt- Wiechers (bugtraq planetcobalt net)
RE: Password complexity - improvement Aug 15 2007 06:12PM
Kunz, Jeffrey T. (JKunz foley com)
SV: Password complexity - improvement Aug 15 2007 05:55PM
Per Thorsheim (putilutt online no)
RE: Password complexity - improvement Aug 15 2007 04:25PM
Bean, John (DSHS) (BeanWj dshs wa gov) (1 replies)
RE: Password complexity - improvement Aug 15 2007 08:44PM
Thor (Hammer of God) (thor hammerofgod com) (1 replies)
RE: Password complexity - improvement Aug 16 2007 05:16PM
James D. Stallard (james leafgrove com) (1 replies)
Re: Password complexity - improvement Aug 16 2007 05:49PM
Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa pacbell net)


 

Privacy Statement
Copyright 2010, SecurityFocus