Password Compexity and Dictionary Lookups

Password Compexity and Dictionary Lookups

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Password Compexity and Dictionary Lookups =?Utf-8?B?SG93YXJkIEdvbGRzdGVp 01-22-2008
Posted by =?Utf-8?B?SG93YXJkIEdvbGRzdGVp on January 22, 2008, 8:52 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We are getting ready to implement complex passwords in our domain. I've done
some testing and it seems there are times when even though I'm meeting all of
the complex passwords requirements, it will still not accept my new password.
I'm curious if by implementing more complex passwords, there is also a
requirement that the passwords can not be easily subjected to dictionary
lookups? I haven't been able to find anything that talks about this so I was
just wondering if it's something I need to warn my users about.

Posted by Roger Abell [MVP] on January 22, 2008, 10:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
It is highly likely your users need to be informed accurately,
but that you do not have a full grasp on the complexity rules.
What do you think they are? In addition to length and change
frequency (separate settings) the complexity requirements are
not just use of 3 of the 4 character sets, but also one cannot
include user name (and there are the other settings controlling
reuse of passwords).

Keep in mind that the existing complexity rules are close to
meaningless, as such as 1Password! will pass but will get
discovered in a rainbow table attempt in very little time.

Perhaps you should not just inform your users of the minimum
to meet the complexity rules, but also advise them on what
makes for a good password (ex. a long phrase).

Roger

> We are getting ready to implement complex passwords in our domain. I've
> done
> some testing and it seems there are times when even though I'm meeting all
> of
> the complex passwords requirements, it will still not accept my new
> password.
> I'm curious if by implementing more complex passwords, there is also a
> requirement that the passwords can not be easily subjected to dictionary
> lookups? I haven't been able to find anything that talks about this so I
> was
> just wondering if it's something I need to warn my users about.



Posted by =?Utf-8?B?QW50ZWF1cw==?= on January 23, 2008, 6:13 am
If you were  Registered and logged in, you could reply and use other advanced thread options
"Howard Goldstein" wrote:

> We are getting ready to implement complex passwords in our domain.

Far more important is to implement retry-lockout, and a mechanism to warn an
Admin where repeated attempts are occurring, since (for a remotely-accessible
account) that might signal a 'bot attack. This approach is far more likely
to protect you from a brute-force attack than are passwords of monster
complexity.

Strangely, the default 2003 Domain Polices DON'T require this.


Similar ThreadsPosted
Lost password on windows 2000 server. Blanked password, but still unable to login September 22, 2006, 5:40 pm
Password Policy forces to change password - but too late... June 27, 2007, 6:32 am
Re: Password June 27, 2005, 7:15 am
Password age July 21, 2005, 2:49 pm
Password September 12, 2005, 8:05 pm
password May 7, 2007, 5:18 am
128 bit password May 7, 2007, 7:43 am
password June 9, 2007, 11:32 am
Password Max Age May 23, 2008, 11:32 am
RE: Administrator password June 20, 2005, 7:33 am

The site map in XML format XML site map

Contact Us | Privacy Policy