I think it’s about fifteen years of password use before all the normal passwords run out. I know this is a general statement, and theoretically there are many millions of passwords possible. However…
There are a finite number of passwords that can be recalled. Depending upon how many demands on shared passwords, a normal family of four runs out of “patterns” in roughly fifteen years. A number that coincides with my experience.
I have cycled through the time limits of most of my secure accounts. That means I have changed so many times in a year that I have to create a new pattern. One interesting side fact is that I can tell how long it has been when I need to access the account by how many different passwords I’ve tried to use. I found one account that still used the first complex password that I made.
And of course, most serious sites only give you three tries before a phone call is necessary. I have used the Apple password app to help me remember odd sites, but it is inconsistent and doesn’t always update automatically.
I’ve noticed that some sites now require 9 characters, at least one capital, at least one number, at least one special character. I had a good pattern for the 8 characters and adding 1 to the end to make it secure seems pointless.
How secure are we really?
I hit a Wall
I think it’s about fifteen years of password use before all the normal passwords run out. I know this is a general statement, and theoretically there are many millions of passwords possible. However…
There are a finite number of passwords that can be recalled. Depending upon how many demands on shared passwords, a normal family of four runs out of “patterns” in roughly fifteen years. A number that coincides with my experience.
I have cycled through the time limits of most of my secure accounts. That means I have changed so many times in a year that I have to create a new pattern. One interesting side fact is that I can tell how long it has been when I need to access the account by how many different passwords I’ve tried to use. I found one account that still used the first complex password that I made.
And of course, most serious sites only give you three tries before a phone call is necessary. I have used the Apple password app to help me remember odd sites, but it is inconsistent and doesn’t always update automatically.
I’ve noticed that some sites now require 9 characters, at least one capital, at least one number, at least one special character. I had a good pattern for the 8 characters and adding 1 to the end to make it secure seems pointless.
How secure are we really?
Share this: