Enforcing Crytographically Strong Passwords

Found on Slashdot on Saturday, 23 April 2005
Browse Various

The WebAppSec mailing list at SecurityFocus is currently having an interesting discussion on how to force users to use cryptographically strong passwords. The original poster suggested displaying a list of randomly generated password for the user to choose from. Two issues pointed with this concept, were Shoulder surfing and the fact that a bunch of randomly generated passwords are hard to remember. A counter proposal was to use pronounceable but randomly generated password. A full summary of this discussion is available.

Well, if you give users a randomly generated password which they cannot change, they will simply write it down and stick a post-it everywhere. You could always start with passphrases: easier to remember, even with 30+ characters.