Defining Password Strength

Passwords13 Las Vegas

Presented by: Jeffrey Goldberg (jpgoldberg)
Date: Tuesday July 30, 2013
Time: 12:00 - 12:15
Location: Main Room
Track: Passwords13

Shannon Entropy is a poor measure of password strength. Guessing Entropy is better but says nothing about a particular password. I propose formal definition of password strength.

Jeffrey Goldberg

Jeffrey Goldberg, aka jpgoldberg, is Chief Defender Against the Dark Arts for AgileBits, the makers of 1Password, where he helps craft and writes about the security design of 1Password. Previously, as mail/sysadmin at a university, he thought passwords would go away "in three to five years". Contrary to popular belief, he is *not* a Sith lord in disguise.

KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats