If the hashed and salted version is available to me, i.e., a leaked password store like Yahoo's, a brute-force against only 18 trillion using current off-the-shelf video card hardware is, well, not going to require a lot of time, frankly.
The only thing that matters is length. Special characters, numbers, smiley faces, whatever, just doesn't matter to a machine. If you're using only 8 characters, that's not enough at present.
However, every one-character increase nets a very large result. Presuming that the site you're using the password on is using proper storage techniques (unfortunately, history shows that typically not to be the case) the content is largely irrelevant so long as the length is adequate.
The only thing that matters is length. Special characters, numbers, smiley faces, whatever, just doesn't matter to a machine. If you're using only 8 characters, that's not enough at present.
However, every one-character increase nets a very large result. Presuming that the site you're using the password on is using proper storage techniques (unfortunately, history shows that typically not to be the case) the content is largely irrelevant so long as the length is adequate.


Comment