We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Have you been hacked?
Options
Comments
-
I have just looked at a couple of password strength checking sites, passwordmonster.com and bitwarden.com.
One password I tried on each site got the following results.
Password monsterVery Strong8 characters containing:Lower case, upper case, numbersTime to crack your password:7 yearsReview: Fantastic, using that password makes you as secure as Fort Knox.
BitwardenYour password strength:weakEstimated time to crack:3 hours
PS: As per the previous post, common sense is the most vital component, along with prudent research and taking on board all comments on sites like this.0 -
So what was the password you tried?0
-
km1500 said:So what was the password you tried?
It was a weak password as identified in my post without any symbols.8 characters containing:Lower case, upper case, numbersIt just goes to show that you need to try at least 2 probably 3 or 4 separate sources for any information website.0 -
"Lower case, upper case, numbers"
That does not help.
Were the letters a word or words, or random.
ie was it something like Bicycle9 or something like eRgv8wlf
both of which are 8 characters containing lower case, upper case, numbers1 -
km1500 said:"Lower case, upper case, numbers"
That does not help.
Were the letters a word or words, or random.
ie was it something like Bicycle9 or something like eRgv8wlf
both of which are 8 characters containing lower case, upper case, numbers4.8kWp 12x400W Longhi 9.6 kWh battery Giv-hy 5.0 Inverter, WSW facing Essex . Aint no sunshine ☀️ Octopus gas fixed dec 24 @ 5.74 tracker again+ Octopus Intelligent Flux leccy0 -
km1500 said:"Lower case, upper case, numbers"
That does not help.
Were the letters a word or words, or random.
ie was it something like Bicycle9 or something like eRgv8wlf
both of which are 8 characters containing lower case, upper case, numbers
1. Weak - Can be cracked in 3 hours
2. Very Strong - Time to crack your password: 7 yearsReview: Fantastic, using that password makes you as secure as Fort Knox.
I do not wish to divulge the password for personal reasons but I have chosen a similar one which actually gives 12 years on password monster.
GSP300kw0 -
yes that is not bad as there are no 'words' as such. My only comment is that 300kw is a valid expression and as such would be better replaced by 3w0k0 for example.0
-
km1500 said:yes that is not bad as there are no 'words' as such. My only comment is that 300kw is a valid expression and as such would be better replaced by 3w0k0 for example.
Surely this should stand as a warning to anyone using a password strength checker.
PS: For what it's worth, I have no intention of ever using a password described as weak on a password checking site.0 -
RG2015 said:Surely two techie websites purporting to measure the strength of a password should not give such dramatically different results for the same password.It's not really that surprising. Password "strength" is a very subjective term, as it's entirely dependent on the way in which someone might go about cracking it. Something like 18atcskd2w might on the face of it not look too bad, but it happens to be on a list of the 25 most common passwords (based on 25 million leaked passwords in 2016). It's therefore likely to be tried in practice long before a traditional brute force (starting at with all the 1 character passwords, then moving on to 2, 3, 4 etc in order) would see it tried. In this context, a password is strong if it doesn't appear in any of the top password lists (of which there are some as long as 1,000,000 entries), and is resistant to a traditional brute force.There is also a question of when the strength meter was calibrated. The typical computing power available to crack passwords has been on a sharp increase, in part due to similar computations being used for cryptocurrency mining. What was considered strong a decade ago might not be today.A third consideration is links to personal information. No password meter is going to help with that. The password Dragons' Den 2023 would be considered strong by most, as none of them would take into consideration that you'd plastered your facebook page with content related to your appearance on the TV show this year.The first consideration when choosing a password is how strong it needs to be. Nobody is panicking because their debit card is only protected by a four digit numeric PIN. Whereas if you've uploaded all of your sensitive data to the cloud using an account protected only by this password, the risk is much higher (it would be unwise to actually do this). In scenarios where strength is important, it should be measured in terms of both uniqueness and complexity.2
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 351.1K Banking & Borrowing
- 253.2K Reduce Debt & Boost Income
- 453.6K Spending & Discounts
- 244.1K Work, Benefits & Business
- 599.1K Mortgages, Homes & Bills
- 177K Life & Family
- 257.4K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards