HomeSecurityHow "Strong" is your password?

How “Strong” is your password?

strong passwordMaybe not as strong as you think! Passwordstrength meters are often misleading.

If you rely on password-to determine how strong your password is, we have some bad news for you. The strength measurements are highly inconsistent and may even lead you astray, according to a new study from researchers at Concordia University:

In our large-scale empirical analysis, it is evident that commonly used strength measures are highly inconsistent, fail to provide coherent feedback, and sometimes provide strength measures that are blatantly misleading.

Researchers Xavier de Carné de Carnavalet and Mohammad Mannan evaluated the password strength metrics used by several popular websites and password managers. Those participating in the study included Apple, Dropbox, Drupal, Google, eBay, Microsoft, PayPal, Skype, Tencent QQ, Twitter, Yahoo, and Russian email provider Yandex Mail. The researchers also looked at popular password managers, including LastPass, 1Password, and KeePass. They also added FedEx and China Railway's customer service center to their study for diversity.

De Carné de Carnavalet and Mannan then compiled a list of nearly 9.5 million passwords available from public dictionaries, including tables from actual password leaks, and ran them through these services during their research.

The rules are ineffective

Password strength meters typically looked at the combinations of characters that make up a password (such as lowercase and uppercase letters, numbers, and symbols). Some tried to detect common words or weak patterns.

However, strength meters that examine password composition often ignore other patterns that are easily broken, and also don't take into account "Leet" transformations, for example, which replace the letter l with the number 1 in an account. Hackers, of course, who try to crack passwords often try these variations.

Contradictory results

The results of the research are quite confusing, with almost identical passwords yielding very different results. For example, the password Paypal01 was considered weak by Skype standards, but strong by PayPal. The password Password1 was considered very weak by Dropbox, but very strong by Yahoo!, and received three different results from three Microsoft checkers (strong, weak, and medium). The password #football1 was also considered very weak by Dropbox, but was perfect for Twitter .

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS