<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title><![CDATA[Password strength]]></title>
    <link>http://brainstorm.ubuntu.com/item/5682/</link>
    <description><![CDATA[Warn users if they try to use a weak password. In the style of google account creation. <br /><br />I originally thought that this would be good for the users login password. However, possibly this could be implemented for all passwords system wide.<br />
<br />


<b>[355 votes] Solution #1: Auto-generated solution of idea #5682</b>
<br />

<br />
<br />



]]></description>

    <language>en-us</language>
    <pubDate>Tue, 25 Mar 2008 12:38:34 +0000</pubDate>
    <lastBuildDate>Fri, 23 Oct 2009 08:13:14 +0000</lastBuildDate>
    <generator>QAPoll module</generator>
    <guid isPermaLink="true">http://brainstorm.ubuntu.com/idea/5682/</guid>
        <item>
  <title>Comment from Auzy</title>
  <description><![CDATA[I may be wrong, but I think this is a dupe of http://brainstorm.ubuntu.com/idea/1198/<br />]]></description>
  <pubDate>Tue, 25 Mar 2008 13:13:05 +0000</pubDate>
</item>
        <item>
  <title>Comment from Eldmannen</title>
  <description><![CDATA[It could also be a right-click option with a context menu, and you select "Verify password strength".]]></description>
  <pubDate>Tue, 25 Mar 2008 19:25:24 +0000</pubDate>
</item>
        <item>
  <title>Comment from spyyder</title>
  <description><![CDATA[System wide implementation would be nice, that way developer could use it in their programs.]]></description>
  <pubDate>Tue, 25 Mar 2008 19:31:15 +0000</pubDate>
</item>
        <item>
  <title>Comment from Eldmannen</title>
  <description><![CDATA[spyyder,<br />Indeed.<br /><br />It could automatically be applied for all software that use a "password field", or as an optional feature to be called.]]></description>
  <pubDate>Tue, 25 Mar 2008 21:58:53 +0000</pubDate>
</item>
        <item>
  <title>Comment from fordplay</title>
  <description><![CDATA[The strength could be determind using a simple points system. For example this 6 point system:-<br /><br />1 point for password 6 or more characters<br />2 points for passwords 8 or more characters<br />2 points for passwords that contain letters and numbers<br />1 point for containing a capital letter<br />2 points for more than 1 capital letter<br />-1 point for repeatition of characters, more than twice.<br />-2 points for password containing words in available wordlists.<br />-2 point for begining a popular password, stored in a new popular passwords wordlist.<br /><br />Results:-<br /> qwerty1234 = -2, 2 points for containing letters and number and -2 for qwerty being in an easy to guess password list and -2 for 1234 being in an easy to guess password list.<br /><br /> BBslwys90 = 6, 2 points for being more than 8 characters, 2 points for containing numbers and letter, 2 points for containing 2 uppercase letters.<br /><br />]]></description>
  <pubDate>Thu, 26 Jun 2008 09:58:47 +0000</pubDate>
</item>
        <item>
  <title>Comment from sandoz</title>
  <description><![CDATA[@fordplay:<br />Your system unfortunately discriminates against other methods of password picking. E.g. the Diceware-method. (see http://en.wikipedia.org/wiki/Diceware )<br /><br />The advantage of the Diceware-method is that you can calculate the strength of the password and that it's using a strongly randomized password picking procedure. For usability reasons it operates with dictionary words, resulting in long, but easy to remember passwords/passphrases.<br /><br />With you system, those strong passphrases would be voted negative, for each word found in the wordlists.<br /><br />So you should add a rule which increases the points with increased length of the password (above 8 characters) to compensate that.<br /><br />And you should modify your rule, that it is used only for the first two/three words found.<br /><br />Just my two cents.<br />]]></description>
  <pubDate>Mon, 30 Jun 2008 08:41:14 +0000</pubDate>
</item>
        <item>
  <title>Comment from fordplay</title>
  <description><![CDATA[@sandoz<br /><br />Good point. My system certainly needs abit of work. However, I feel that something similar would be good enough to remind users that '1234' or 'password' is not a good password.<br /><br />Some further read on password strengh.<br />Leaked password analysis.<br />http://www.the-interweb.com/serendipity/index.php?/archives/94-A-brief-analysis-of-40,000-leaked-MySpace-passwords.html<br /><br />Ajax version of something similar<br />http://phiras.wordpress.com/2007/04/08/password-strength-meter-a-jquery-plugin/<br />]]></description>
  <pubDate>Tue, 01 Jul 2008 11:17:06 +0000</pubDate>
</item>
        <item>
  <title>Comment from yzarc</title>
  <description><![CDATA[please don't, if I was a newbie decided to give linux a try by ubuntu and must build a alien password I just give up after the third attempt or just format the HD when I forgot the password. the people who needs strong passwords know this, don't make the life harder for my "grandmother" :D.]]></description>
  <pubDate>Wed, 06 Aug 2008 12:25:22 +0000</pubDate>
</item>
      </channel>
</rss>
