Random password experiment

Brian Mearns bmearns at ieee.org
Tue Jun 23 15:44:04 CEST 2009

Hey folks,

Sorry, this is off-topic, but I thought all the security folks who
lurk and participate on this list might be interested.

I'm doing a little investigation, and I could use some experimental
data. For those who would like to participate, I'd like you to
generate some random passwords and send them to me. I need 5
passwords per person, but you should generate them one at a time,
then wait at least an hour before generating the next, to keep them
pretty much independent. The passwords should be *random* strings of
characters that you just pull out of your head, no words or birthdays
or anything like that, just sit down and come up with a random
string that: a) you think makes a secure** random password, and b)
you think you could memorize within a few days or a week and use as
your main password (for instance, for logging in to your computer).

The only limitation is the passwords can only contain upper- and
lower- case letters, the digits 0-9, and the following punctuation
marks: a dot (.), and dash (-), and an underscore (_). It doesn't
have to contain all of those characters, of course, but that's your
working alphabet.

If you want to participate, please send the "passwords" to me by
email. You can feel free to encrypt them if you'd like, my key-id
is listed in the signature. I'm hoping to have some interesting
results to report in the next few weeks. (And no, I'm not going to
try to break into anyone's system, but you obviously shouldn't be
sending me passwords you actually use or will use anyway).

- -Brian

** - For whatever your definition of "secure" is.

