“How Big is Your Haystack?”

There are three interesting things on this page:

  • An “interactive brute force search space calculator” for passwords, which you can play with to get a good idea how easily a brute-force attack would find YOUR passwords.

  • Some comments further down the page on mathematical entropy, and how it doesn’t affect password strength (despite common wisdom on the subject) nearly as much as pure password length.

  • A description of a “password padding” system that looks like it would generate strong and remember-able passwords.

I have reason to know the math for this kind of thing myself, and it all looks pretty accurate. Of course, a “password safe” with truly random passwords (and a really good backup system) is the best way to go these days, hands down, but there will always be a few passwords that you’ll need to keep in your wetware.