Regístrese ahora para una mejor cotización personalizada!

How long should a password be in 2023? You're asking the wrong question

Oct, 25, 2023 Hi-network.com
Valeriia Mitriakova/Getty Images

A longer password is more secure. It's just common sense, right? Increasing the length of a password means there are more combinations available. That in turn means a brute force attack, in which someone uses an automated system to try every combination in an effort to crack the code, will take longer.

Also: The best password managers

Security experts generally agree that a password of eight characters is too easy to crack with the help of readily available hardware like the GPU in a gaming PC. Using an Nvidia RTX 4090, for example,Hive Systems calculated that it would take less than an hour to blast through every possible 8-character combination of letters (capital and lowercase) and numbers and symbols. That's twice as fast as a mainstream graphics card from two years ago, in yet another example of Moore's Law in action.

So, if eight characters is too short, how long is long enough? Is there a magic number? Security experts don't agree on the exact number, I discovered in a review of published recommendations from a wide range of sources. But they have reached a broad consensus: At least 12 characters, but more is better. And maybe a passphrase consisting of four or more random words is best of all. 

Also: What are passkeys? Experience the life-changing magic of going passwordless

Every expert we surveyed agreed that increasing the length of a password is much more important than adding complexity requirements, such as mandating the use of numbers, letters, and symbols. But even more important is ensuring that the password is truly random. Add all that together and you get a measurement calledentropy, which measures the difficulty of guessing a password.

An attacker who can make educated guesses is likely to make short work of breaking a low-entropy password based on your dog's name and the year you were born; a truly random password assigned by a password manager is much more of a challenge.

But how long?

In an article at the Infosec Institute website, Daniel Brecht examines "Password security: Complexity vs. length," and makes a case for 12 characters being a good starting point:

Short length passwords are relatively easy to break, so the idea is to create lengthier ones for added security and to make them less predictable. So what is the desired or required length? A 2010 Georgia Tech Research Institute (GTRI) study told how a 12-character random password could satisfy a minimum length requirement to defeat code breaking and cracking software, said Joshua Davis, a research scientist at GTRI. Richard Boyd, a senior researcher at GTRI says, "Eight-character passwords are insufficient now... and if you restrict your characters to only alphabetic letters, it can be cracked in minutes." In any case, to be on the safe side, a password length of 12 characters or more should be adopted.

The developers of some popular password managers agree in principle. At theBitwarden Blog , for example, the answer is authoritative and punctuated with an actual exclamation point: "Make your password 14 to 16 characters or more!"

That's not just a random recommendation, either. Bitwarden's advice is derived from a National Institute of Standards and Technology (NIST) publication, NIST SP 800-63B - Digital Identity Guidelines, which notes, "Users should be encouraged to make their passwords as lengthy as they want, within reason. Since the size of a hashed password is independent of its length, there is no reason not to permit the use of lengthy passwords (or pass phrases) if the user wishes."

Also: The best VPN services: Expert tested and reviewed

Meanwhile, rival 1Password has a similar take in their blog post,which confidently asserts , "This is how long your passwords should be": "1Password's default generated password length is 19 or 20 characters, depending on the version. But that's actually overkill! When a password is properly generated, 11

tag-icon Etiquetas calientes: tecnología Nuestro proceso seguridad

Copyright © 2014-2024 Hi-Network.com | HAILIAN TECHNOLOGY CO., LIMITED | All Rights Reserved.