Wayne Anderson | 17 Jul 2010 06:27

RE: TGP Password Strength Checker online

I think this brings up a slightly more important question.

What are you trying to accomplish here?  
Who are you trying to reach with this?

Please don't get me wrong.  I like this application.  It's free.  It's
straightforward for someone already familiar with PKI mechanisms and similar
applications.  It works as advertised at the moment.

I think as the developer you have to think about whether you intend this to
be yet another niche application choice for those of us already in the
security profession (and assumedly familiar with other offerings in the
space) OR if, as I see this application having the potential to do, making
encryption more accessible for a lower-functional-capability user base.  

If the latter, then it brings up simplification of the UI (or at least a
config choice to use a simple UI).  And it also then brings up the point
that I made.  You know what class F is.  I know what class F is.  That
lower-class-of-user doesn't understand what class F is, what it means, how
likely it is an attacker would have access to a
billion-permutations-per-second capable configuration to use as a brute
force platform,  etc.  Yes, absolutely, its words and graphics and window
dressing, but I think this application has great potential for those
interested in encryption but intimidated by the details of using real x509
PKI, etc, etc.

The other point that I would make here is even if the choice you make is
that you don't care about having the capability to make encryption more
accessible.  Even if you say "I put this out there because there is a
community that might like to use this tool and I wanted to play with some
(Continue reading)

Thor (Hammer of God | 17 Jul 2010 22:53

RE: TGP Password Strength Checker online

OK, you sold me.  ;)

Please see updated options and documentation at:

http://www.hammerofgod.com/passwordcheck.aspx

I give the classes of attack, but I don't have any real reference to what the classes represent nor could I
find any (well, I found one, but it didn't seem accurate).  So, if  you would like to come up with some
analogous references (as in, what it takes to get 1,000,000,000 per second) then let me know and I'll post them.

t

>-----Original Message-----
>From: listbounce <at> securityfocus.com [mailto:listbounce <at> securityfocus.com]
>On Behalf Of Wayne Anderson
>Sent: Friday, July 16, 2010 9:28 PM
>To: Thor (Hammer of God) TGP; 'Murda'; focus-ms <at> securityfocus.com;
>'Serban Oprescu'
>Subject: RE: TGP Password Strength Checker online
>
>I think this brings up a slightly more important question.
>
>What are you trying to accomplish here?
>Who are you trying to reach with this?
>
>Please don't get me wrong.  I like this application.  It's free.  It's
>straightforward for someone already familiar with PKI mechanisms and similar
>applications.  It works as advertised at the moment.
>
>I think as the developer you have to think about whether you intend this to
(Continue reading)


Gmane