Password choices

The Polymath hollombe at ttidca.TTI.COM
Fri Jul 8 05:08:50 AEST 1988


In article <4387 at ptsfa.PacBell.COM> jmc at ptsfa.PacBell.COM (Jerry Carlin) writes:
}Somewhere I remember hearing or reading that someone did a study
}about typical (bad) password choices and/or what consituted good
}password choices. ...

Suggested reading:

     UNIX System Manager's Manual
	  On the Security of UNIX
	  Password Security - A Case History

I did some experimenting and reading on the subject a few months ago.
Here's some suggestions:

Bad choices:

     anything under 6 characters
     anything in the spell dictionary (or any on-line dictionary)
     anything in your /etc/passwd entry (especially name and login id)
     any publicly available personal fact or attribute

Good choices:

     not a bad choice (-:
     include at least one punctuation (non-alphameric) character
     use both upper and lower case

-- 
The Polymath (aka: Jerry Hollombe, hollombe at ttidca.tti.com)  Illegitimati Nil
Citicorp(+)TTI                                                 Carborundum
3100 Ocean Park Blvd.   (213) 452-9191, x2483
Santa Monica, CA  90405 {csun|philabs|psivax|trwrb}!ttidca!hollombe



More information about the Comp.unix.questions mailing list