Secret Microsoft policy limited Hotmail passwords to 16 characters

PrincessFrosty

Platinum Member
Feb 13, 2008
2,300
68
91
www.frostyhacks.blogspot.com
That's retarded...

They argue uniqueness matters most and that's rubbish, first of all that doesn't make any sense, how do you make a password that is more unique than any other, maybe they mean random, or unpredictable?

But secondly, length is generally considered to be much safter than "uniqueness", a longer passphrase with small character set is computationally harder to brute force than a smaller passphrase with a very large character set.

I literally have been playing with password brute forcing over the last few days and you can break a password of 1-7 characters long hashed with a fast GPU, precalculated rainbow tables and just a few minutes of computation. That's using a wide character set of all Upper and lower case Alpha, numeric and special symbols including space.

In comparison just extending that to 10 length password even with just lower alpha requires so much computational time that only super computer are going to break it within your life time. 10+ just isn't possible with the hardware we have right now, or for the forseeable future.

There's a great XKCD comic on this:

http://xkcd.com/936/
 

JimKiler

Diamond Member
Oct 10, 2002
3,561
206
106
i wish my company would allow no special characters if we hit say 12 or more characters. I hate trying to guess what is and is not a special character between all the systems we use.
 

bononos

Diamond Member
Aug 21, 2011
3,928
186
106
......

In comparison just extending that to 10 length password even with just lower alpha requires so much computational time that only super computer are going to break it within your life time. 10+ just isn't possible with the hardware we have right now, or for the forseeable future.

There's a great XKCD comic on this:

http://xkcd.com/936/

Maybe M$soft doesn't want people doing long passphrases like the horsebatterystaplething.

Perhaps a few years ago without gpgpus in the mix, a minimum of 10 characters would've been reasonble, now 10 chars is a little short and quite possible to bruteforce even without supercomputers. I'd say 12+ would be the minimum.
 

bononos

Diamond Member
Aug 21, 2011
3,928
186
106
Actually now I think the limitation might be push more users to the new outlook.com.