https://www.youtube.com/watch?v=wVyu7NB7W6Y
This is one reason the net is going to long passphrases. The two-factor authentication touted as being secure is NOT secure.
1. Longer passwords are harder to crack:
- Longer passwords contain more characters, making them more difficult for computers to guess through brute force attacks (trying many combinations).
- According to the FBI, "Password length is more important than complexity. Instead of using short, complex passwords, use passphrases that combine multiple words and are longer than 15 characters."
2. Length vs. complexity:
- While complex passwords with special characters can be secure, length is often more important than complexity alone.
- Simple but long passphrases like "cheetah scream teleport crocodile" can be more secure than shorter complex passwords like "W@5h1ngt0N!".
3. Easier to remember:
- Longer passphrases made of actual words are often easier for users to remember than complex short passwords.
- This can reduce risky behaviors like writing down passwords or reusing them across accounts.
4. Statistical findings:
- Research from Specops found that 85% of compromised passwords are under 12 characters in length.
- However, even 15-character passwords were the 8th most commonly compromised length, showing length alone isn't foolproof.
5. Practical limits:
- For passwords stored in password managers, there may be diminishing returns beyond certain lengths (e.g., 42 characters for Bitwarden) due to encryption limitations.
- Some systems may have maximum length restrictions.
6. Other factors matter:
- Length alone doesn't protect against phishing, password reuse, or database breaches.
Citations:
[1] https://www.blueridge.tech/2023/11/20/longer-passwords-are-better-but-still-not-good-enough/
[2] https://specopssoft.com/blog/longer-passwords-protect-compromise/
[3] https://www.tech.gov.sg/media/technews/why-passphases-are-much-more-secure-than-passwords/
[4] https://www.infosecinstitute.com/resources/security-awareness/password-security-complexity-vs-length/
[5] https://www.reddit.com/r/Bitwarden/comments/16v2lqc/42_character_password_are_longer_than_that_more/
[6] https://www.relativity.com/blog/passwords-101-how-theyre-hacked-and-why-longer-is-better/
Exposing the flaw in our phone system
Edited #1