how long should a password be?

Wolf Canis wolf.canis at googlemail.com
Mon May 5 09:55:06 CEST 2008


Matt Kinni wrote:
> Everyone says it should be as long as possible, but there comes a point
> where it's just impossible to remember anything longer than 20
> characters.  What do you think?
Hello,
I would say a password should be between 8 - 12 characters long. But
that isn't that important. Eight characters is long enough if you apply
these
rules:
a) All characters alowed -  a-z , A-Z, 0-9, all special characters
b) Have a system :  For example: Take a sentence as basis for your
passphrase:
    Sentence (Clue): This is my 1st sentence as basis for very long
passphrase!
    The resulting passphrase could be:
                                                Tim1ssabfvlp!
                       OR
                                                hsysesaoeoa!
                      OR
                                                !Tpilmv1fsba
                     and so on

You get it?

There are infinite possibilities. That's the trick. Not the length of a
password is
decisive but the quality. The quality of your password decides how much
effort is necessary to hack it.

Hope that helps.

W. Canis



-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 260 bytes
Desc: OpenPGP digital signature
URL: </pipermail/attachments/20080505/f57444e1/attachment-0001.pgp>


More information about the Gnupg-users mailing list