assurance - [Assurance] RE: Question about entropy calculator
Subject: Assurance
List archive
- From: Eric Goodman <>
- To: "" <>
- Subject: [Assurance] RE: Question about entropy calculator
- Date: Fri, 2 May 2014 16:00:48 +0000
- Accept-language: en-US
Going straight off of NIST, 94 characters plus complexity rules is 32 bits of entropy. To get Bronze, you must limit total possible guesses to 1:2^10, which means you can allow 2^22 (~420,000) guesses. For Silver the limit is 1:2^14, so you’d have to limit to 2^18 (~26,000) guesses. Your setup allows roughly 5 guesses every 10 minutes, which is 30 guesses an hour, 720 a day, and 262,800 in a year (at which point you force a reset). So you’d be good for Bronze and close, but not quite there
for Silver. --- Eric From: [mailto:]
On Behalf Of Yates, Bry-Ann L Hello, It would seem to be is easier for us to reach LOA 2 in the K column then reach the LOA 1 section in column J on the “94characters” tab under the “94 characters set, Plus complexity rules” section.
1.
We would like to have a minimum password of 10 complex characters. 2.
Allow for 5 guesses before lockout. 3.
A lockout for 10 min, which we are entering as .6 4.
Force the password change every 365 days. This makes row 24, column F (length) and K (LOA2) green, but leaves column J(LOA1) orange. I believe LOA1 needs to be green for Bronze, is that correct?
Can someone help me interrupt what is needed. Thank you, Bry-Ann |
- [Assurance] Question about entropy calculator, Yates, Bry-Ann L, 05/01/2014
- Re: [Assurance] Question about entropy calculator, Dana Watanabe, 05/02/2014
- [Assurance] RE: Question about entropy calculator, Eric Goodman, 05/02/2014
Archive powered by MHonArc 2.6.16.