Might sound bloody obvious but - don't use dictionary words in your
passwords, don't even use 1337ified dictionary words.
If you use random 8 character combinations of upper & lower case alpha,
numerals & punctuation a dictionary attack is going to cause a bit of load
on the server & some unwanted bandwidth. At worst you are looking at a DOS
style attack.
Another very easy but not so secure option is listfirst(createUUID,'-').
Still much better than a dictionary word.
I'm assuming that if the info on your page is serious enough to warrant
concern about dictionary attacks the users would be willing to use whatever
password they are given. Eg. I'm quite happy that my online banking insists
I pick a good password.
I've got a site that requires a username and password that is either
selected by the user or their company administrator. From what I can see at
least 80% of passwords are based on some part of their name, job title,
company name or a word that appears on the login screen like 'welcome',
'login' or 'password'. In this case it doesn't really matter as there are no
serious security risks in the site's functionality and ease of use is the
bigger issue, but if there was confidential info on the site this type of
freedom with passwords would be a major headache.
Password Type 10^6 (millions
of
combinations)
--------------------- ----------
english language words * 0.65
6 random alpha characters (not case sensitive) 308.92
8 characters from the start of a UUID (not case sensitive) 4294.97
8 random alpha characters (not case sensitive) 208827.06
8 random alpha characters (case sensitive) 53459728.53
8 random alpha, numeric & punct. chars (case sensitive) 806460091.89
* according to http://hypertextbook.com/facts/2001/JohnnyLing.shtml -
although the average person only knows 20,000 words.
Cheers
Mark
______________
Mark Stanton
Web Production
Gruden Pty Ltd
Tel: 9956 6388
Mob: 0410 458 201
Fax: 9956 8433
www.gruden.com
---
You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
To unsubscribe send a blank email to [EMAIL PROTECTED]
MX Downunder AsiaPac DevCon - http://mxdu.com/