Making Password Meters Great Again

BSidesLV 2016

Presented by: Adam Caudill
Date: Wednesday August 03, 2016
Time: 11:00 - 11:50
Location: Tuscany
Track: Passwords

Password meters have become ubiquitous, some are decent, but the majority are actually harmful. While attempts have been made to create strength meters that better reflect the realities of how passwords are cracked, most meters though are naive to such a degree that they give an incredibly dangerous false since of security.

This talk looks at the best and worst of current password meters - from the useful education they provide, to the absurd feedback that has become so common. To address the flaws in current methods, a new method for calculating the real-world strength of passwords is introduced. Based on the techniques used in cracking passwords, including hashing details, a new method has been developed to provide more useful information about the actual strength of a password.

Adam Caudill

Adam Caudill is a security consultant with over 15 years of experience in security and software development; with a focus on application security, secure communications, and cryptography. Active blogger, open source contributor, and advocate for user privacy and protection. His work has been cited by many media outlets and publications around the world, from CNN to Wired and countless others.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats