Brian Blake random.rodder at gmail.com
Fri Mar 25 14:43:16 EDT 2011

On Fri, Mar 25, 2011 at 2:28 PM, gene heskett <gheskett at wdtv.com> wrote:

> The security issue is, as I see it, the short password.  A 6 character PW
> can be found by John the Ripper in just a few seconds.

When I set that limit I was taking into consideration the possible blow-back
of people who did not want to have passwords that long.
I'm trying to keep the forum safe yet still keep it friendly enough for
folks to use and enjoy.Six is the minimum length, they can have
up to a 100 characters if they want and can remember it...

>  My own minimum user
> password length is 9,

Mine is longer... no joke intended...

> and my root PW on this machine is, lets just say,
> more than 20.

My admin passwords are not quite that long, but, I can guarantee none of my
passwords will ever be found by a dictionary attack...

>  Same for the admin password on dd-wrt.  John would have to
> work till the universe runs down to find those, as every character added
> adds to the factorial on the difficulty. To illustrate, a 6 char PW is
> 6!=720. 9!=362880. and 20!=2.43290200818e+18, a rather large number.
> You have to make it expensive enough to crack your password that they get
> bored and go looking for easier targets.
