Skip to content

How Secure is Your Password?

October 16, 2009
tags:
by Xcentric

You’ve probably heard about the importance of having a ‘strong’ password, and may even have an enforced password policy at work.  But, what difference does using capital letters, numbers and symbols really make?  Actually, A LOT that your security could depend on.

Did you know that an eight character password that is all lowercase letters would only take about 2.4 days to crack?  That’s how long it would take the average hacker’s computer to process through every possible password combination for those 8 letters.  That’s scary!  But, the good news is that just adding a CAPITAL letter and an *asterisk* would lengthen the time for that same computer to process through all the possible password combinations to 2.1 centuries.  That’s more like it!

Basically, with today’s technology, it’s only a matter of time before a computer runs through all of the password possibilities for a given number of characters- or gets shut down trying.  That’s why making sure your passwords are strong enough is so critical.

Here’s a look at how long it would take the average computer to run through every possible password for a given number of characters (link):

Password Length All Characters Only Lowercase
3 characters
4 characters
5 characters
6 characters
7 characters
8 characters
9 characters
10 characters
11 characters
12 characters
13 characters
14 characters
0.86 seconds
1.36 minutes
2.15 hours
8.51 days
2.21 years
2.10 centuries
20 millennia
1,899 millennia
180,365 millennia
17,184,705 millennia
1,627,797,068 millennia
154,640,721,434 millennia
0.02 seconds
.046 seconds
11.9 seconds
5.15 minutes
2.23 hours
2.42 days
2.07 months
4.48 years
1.16 centuries
3.03 millennia
78.7 millennia
2,046 millennia

With that said, it’s a good idea to set up an enforced password policy at work, if there isn’t one in place already.  Here’s a sample policy that requires users to change their login password every 90 days based on the following set of complexity requirements:

  • Passwords may not contain all or part of the user’s account name
  • Passwords must be at least 8 characters in length
  • Must contain characters from 3 of the following 4 categories:
    1 – English uppercase characters (A through Z)
    2 – English lowercase characters (a through z)
    3 – Base 10 digits (0 through 9)
    4 – Non-alphabetic characters (for example, !, $, #, %)


No comments yet

Leave a Reply

Note: You can use basic XHTML in your comments.

Subscribe to this comment feed via RSS