Pass or fail: A new test for password legitimacy
A. Cherry, M.W. Henderson, W.K. Nickless, R. K. Olson, G. Rackow · University of North Texas Digital Library (University of North Texas) · 1992
While other programs check for bad passwords after the fact, it is important to have good passwords at all times, not just after the latest Crack run. To this end we have modified Larry Wall's Perl password program and added, among other features, the ability to check a sorted list of all the "bad passwords" that Crack will generate, given all the dictionaries that we could get our hands on (107 MB of unique words, so far). The combination of improvements has turned publicly available code into a powerful tool that can aid sites in the maintenance of local security. 1 The Problem Our motivation for developing a new test for passwords was based on the following assumptions: ffl There is some cracker out there on The Net who has our password file and nothing better to do. ffl Every so often we find out that someone is trying to break into our systems. ffl Having weak passwords on a system is an invitation for trouble, especially when connected to the Internet. ffl Stock passwd as i...