OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Password complexity - improvement

From: Ansgar -59cobalt- Wiechers (bugtraqplanetcobalt.net)
Date: Thu Aug 16 2007 - 16:09:56 CDT


On 2007-08-16 Thor (Hammer of God) wrote:
>>> Is there a way to enforce all 4 properties.
>>
>> Enforcing passwords that MUST consist of uppercase letters, lowercase
>> letters, numbers AND special characters reduces the total number of
>> possible passwords, which in consequence has a negative impact on
>> your security.
>
> Just to follow up, this is incorrect. More possible source characters
> == more possible combinations. Can you elaborate on what you mean by
> this?

This is not about more possible source characters. The amount of source
characters is exactly the same in both cases. I'm talking about limiting
the possible combinations out of these source characters. See my other
reply.

Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq