17 Jul 2010 06:27
RE: TGP Password Strength Checker online
Wayne Anderson <wfrazee <at> wynweb.net>
2010-07-17 04:27:47 GMT
2010-07-17 04:27:47 GMT
I think this brings up a slightly more important question. What are you trying to accomplish here? Who are you trying to reach with this? Please don't get me wrong. I like this application. It's free. It's straightforward for someone already familiar with PKI mechanisms and similar applications. It works as advertised at the moment. I think as the developer you have to think about whether you intend this to be yet another niche application choice for those of us already in the security profession (and assumedly familiar with other offerings in the space) OR if, as I see this application having the potential to do, making encryption more accessible for a lower-functional-capability user base. If the latter, then it brings up simplification of the UI (or at least a config choice to use a simple UI). And it also then brings up the point that I made. You know what class F is. I know what class F is. That lower-class-of-user doesn't understand what class F is, what it means, how likely it is an attacker would have access to a billion-permutations-per-second capable configuration to use as a brute force platform, etc. Yes, absolutely, its words and graphics and window dressing, but I think this application has great potential for those interested in encryption but intimidated by the details of using real x509 PKI, etc, etc. The other point that I would make here is even if the choice you make is that you don't care about having the capability to make encryption more accessible. Even if you say "I put this out there because there is a community that might like to use this tool and I wanted to play with some(Continue reading)
RSS Feed