how long should a password be?

Noiano noiano at x-privat.org
Mon May 5 09:40:03 CEST 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Matt Kinni wrote:
> Everyone says it should be as long as possible, but there comes a point
> where it's just impossible to remember anything longer than 20
> characters.  What do you think?

Well IMHO you should merge together some significant (just
for you!) events, hard to forget, and turn them into a password.
It should be
- - longer >= 25 IMHO
- - nonsense in any language to avoid dictionary attack
- - contain special character such as !?$£()...

Noiano
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iE8DBQFIHrnS+JjGoasQ6NIRCC4yAOCKodHXmpyqfcMl6+jhu5a3ZdzsNnesFfhL
pVrPAOCAp6SMeXSFBGduthirWlahq8JIzKkRXWyihnYP
=oJln
-----END PGP SIGNATURE-----




More information about the Gnupg-users mailing list