Learn about 5 common password security myths, plus the importance of password entropy, password length and proper password storage. How long it would take a computer to crack your password? The strength of a random password as measured by the information entropy is just the base-2 logarithm or log 2 of the number of possible passwords, assuming each symbol in the password is produced independently. But if a hacker has stolen your username and the MD5 hash value of your password from a company's server, and the rainbow table of the hacker contains this MD5 hash, then your password will be cracked quickly. Later research into human-selected password entropy using available real world data has demonstrated that NIST scheme does not provide a valid metric for entropy estimation of human-selected passwords. The comic illustrates the relative strength of passwords assuming basic knowledge of the system used to generate. While the strength of randomly chosen passwords against a brute force attack can be calculated with precision, determining the strength of human-generated passwords is challenging. Unfortunately, many authentication systems in common use do not employ salts and rainbow tables are available on the Internet for several such systems. Do not use something that can be cloned but you can't change as your passwords, such as your fingerprints. However, such passwords are typically the hardest to remember.

How to Choose a Password - Computerphile



