Hasil (
Bahasa Indonesia) 1:
[Salinan]Disalin!
Password Selection StrategiesThe lesson from the two experiments just described (Tables 3.1 and 3.2) is that,when not constrained, many users choose a password that is too short or too easyto guess. At the other extreme, if users are assigned passwords consisting of eightrandomly selected printable characters, password cracking is effectively impossible.But it would be almost as impossible for most users to remember theirpasswords. Fortunately, even if we limit the password universe to strings of charactersthat are reasonably memorable, the size of the universe is still too large topermit practical cracking. Our goal, then, is to eliminate guessable passwords whileallowing the user to select a password that is memorable. Four basic techniquesare in use:• User education• Computer-generated passwords• Reactive password checking• Proactive password checkingUsers can be told the importance of using hard-to-guess passwords and can beprovided with guidelines for selecting strong passwords. This user education strategyis unlikely to succeed at most installations, particularly where there is a largeuser population or a lot of turnover. Many users will simply ignore the guidelines.Others may not be good judges of what is a strong password. For example, manyusers (mistakenly) believe that reversing a word or capitalizing the last letter makesa password unguessable.
Sedang diterjemahkan, harap tunggu..
