<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Varun&#039;s Whiteboard on Technology &#187; policy</title>
	<atom:link href="http://paheli.net/blog/category/policy/feed/" rel="self" type="application/rss+xml" />
	<link>http://paheli.net/blog</link>
	<description>Everything is a Puzzle waiting to be solved!</description>
	<lastBuildDate>Fri, 17 Sep 2010 19:13:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Choosing good passwords &#8211; memorability and security</title>
		<link>http://paheli.net/blog/2007/12/06/choosing-good-passwords-memorability-and-security/</link>
		<comments>http://paheli.net/blog/2007/12/06/choosing-good-passwords-memorability-and-security/#comments</comments>
		<pubDate>Thu, 06 Dec 2007 09:01:52 +0000</pubDate>
		<dc:creator>Varun</dc:creator>
				<category><![CDATA[policy]]></category>
		<category><![CDATA[memorability]]></category>
		<category><![CDATA[paper]]></category>
		<category><![CDATA[password policy]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.paheli.net/blog/2007/12/06/choosing-good-passwords-memorability-and-security/</guid>
		<description><![CDATA[Password policies are an integral part of security for most computing facilities. Even though passwords have supposedly outlived their usefulness they are still the single most common security control for authentication for online systems. Thus having a user-friendly but secure enough password policy and enforcing it is very important. An administrator usually has the ability [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><!-- End Shareaholic LikeButtonSetTop Automatic --><p>Password policies are an integral part of security for most computing facilities. Even though passwords have supposedly outlived their usefulness they are still the single most common security control for authentication for online systems. Thus having a user-friendly but secure enough password policy and enforcing it is very important.</p>
<p>An administrator usually has the ability to set the acceptable password policy for a system. However common questions that arise are &#8211; What is the minimum length of a password? How many non-alpha characters (numbers and special symbols) should it have? Are there any restrictions on using both uppercase and lowercase characters? And many more.</p>
<p>I just read a reasonably old but very useful paper titled <a href="http://citeseer.ist.psu.edu/315989.html" title="The Memorability and Security of Passwords Some Empirical Results (2000) by  Jianxin Yan, Alan Blackwell, Ross Anderson, Alastair Grant">The Memorability and Security of Passwords Some Empirical Results</a> authored by <span class="m">   Jianxin Yan, Alan Blackwell, Ross Anderson and Alastair Grant. It is short 11-page paper describing an experiment carried out on approximately 400 students that gives empirical results on the memorability and security of passwords chosen via 3 different approaches &#8211; allow user to select, random password, mnemonic passphrase.</span></p>
<p>In a nutshell the paper recommends users to choose mnemonic passwords that are at least 8 characters long, preferably longer with individual characters being a mixture of letters, numbers and special symbols.</p>
<p>And while  you are at it do read this article by Bruce Schneier &#8211; <a href="http://www.schneier.com/blog/archives/2007/01/choosing_secure.html" title="Choosing Secure Passwords by Bruce Schneier">Choosing Secure Passwords</a>. He talks about a password recovery program called <a href="http://www.accessdata.com/common/pagedetail.aspx?PageCode=proddec" title="Password Recovery Toolkit from AccessData">PRTK</a> that assumes that all passwords are made up of a root (need not be a dictionary word but is usually pronounceable) and an appendage (a suffix or prefix to the root). His recommendations for a difficult to crack password:</p>
<blockquote><p>So if you want your password to be hard to guess, you should choose something not on any of the root or appendage lists. You should mix upper and lowercase in the middle of your root. You should add numbers and symbols in the middle of your root, not as common substitutions. Or drop your appendage in the middle of your root. Or use two roots with an appendage in the middle.</p>
<p>Even something lower down on PRTK&#8217;s dictionary list &#8212; the seven-character phonetic pattern dictionary &#8212; together with an uncommon appendage, is not going to be guessed. Neither is a password made up of the first letters of a sentence, especially if you throw numbers and symbols in the mix.</p></blockquote>
<p>Interesting.</p>
<div class="shr-publisher-9"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://paheli.net/blog/2007/12/06/choosing-good-passwords-memorability-and-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

