From: Chad Perrin Date: 2010-08-29T21:26:09+09:00 Subject: Re: If input contains.... --DocE+STaALJfprDB Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable I may be a little late to this thread, but . . . what the heck. On Tue, Aug 24, 2010 at 10:39:17PM +0900, Peter Hickman wrote: > That is not going to be very secure. Agreed. It is extremely common for brute force attacks to make use of translations to "leetspeak" as well as dictionary words before they start using any kind of "randomness". The prevalence of leetspeak translators one can find via Google is a testament to how common and easy it is to make such translations: https://encrypted.google.com/search?q=3Dleetspeak+translator When something is that easily found on the Web, and could be part of the process of cracking your security, you can bet it's going to be a common part of the toolkit used by malicious security crackers. >=20 > This is what I use when I need a username or password for some part of > my system [snip] I use something similar, in a fairly complex script of my own, when I don't just use the random password generator built into pwsafe. --=20 Chad Perrin [ original content licensed OWL: http://owl.apotheon.org ] --DocE+STaALJfprDB Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.14 (FreeBSD) iEYEARECAAYFAkx6UTAACgkQ9mn/Pj01uKV1LQCggFRNIy3Q3f/5wR5c08svOCbK CFkAoIOQKca0zIf/xQz7Vtwit6PPxgjK =4JiV -----END PGP SIGNATURE----- --DocE+STaALJfprDB--