Skip to main content

Web consultant says meters don’t measure true strength of passwords

have i been pwned owner uncovers 13 million plaintext passwords leaked from free webhost is a safe password even possible we
guteksk7/Shutterstock
We’ve all gone through the process of trying to sign up for a website, only to be told our password isn’t strong enough. But these password strength meters may not be all they’re cracked up to be and may be only giving the illusion of security.

According to Mark Stockley, founder of web consultancy Compound Eye, these meters don’t actually measure strength at all. Stockley tested five different password meters, first in March 2015 and then 18 months later. He says none of them improved during that time.

Writing for Sophos, he explained that password meters only attempt to measure how long it would take to crack the password. A meter on the website typically suggests you use a long password with uppercase and lowercase characters and symbols like question marks and exclamation points.

“A strong password is one that is highly resistant to attempts to crack it with online or offline dictionary attacks,” he said. “The only good way to measure the strength of a password is to try and crack it — a serious and seriously time-consuming business that requires specialist software and expensive hardware.”

As part of his tests, Stockley ran five passwords that he deemed terrible through the meters. If the meters were up to par, they would reject them. The five passwords were “abc123,” “trustno1,” “ncc1701,” “primetime21,” and “iloveyou!” More often than not, the passwords passed the meter with some getting a “good” or “normal” result.

To further corroborate his findings, Stockley was able to crack these five passwords with the open source tool John the Ripper, making it clear that the passwords weren’t cut out for securing your accounts.

So nothing had improved in over a year. In his latest tests, Stockley added a sixth password meter, the very popular zxcvbn, which is used by Dropbox and WordPress. It deemed all five terrible passwords “very weak,” marking something of an improvement.

However, Stockley still remains highly critical of password meters that “muddy the waters with misleading or ambiguous terminology and colors,” and encouraged the use of two-factor authentication.

Editors' Recommendations

Jonathan Keane
Former Digital Trends Contributor
Jonathan is a freelance technology journalist living in Dublin, Ireland. He's previously written for publications and sites…
How to check your CPU temperature
Acer ROG Strix Review CPU

Checking your CPU's temperature is a great way to make sure that your processor is running at peak performance, as a processor that's too hot can cause all kinds of common PC problems, from throttled performance to crashes. There are a number of different ways to check your CPU temperature, and you may have some of the applications installed already.

Whether you're looking to troubleshoot a PC problem or are interested in testing your processor's performance, here are the best ways to check your processor's temperature.

Read more
Meta Smart Glasses just got the AI upgrade I’ve been waiting for
Phil Nickinson wearing the Apple AirPods Pro and Ray-Ban Meta smart glasses.

Meta loves to upgrade its hardware with extra features, and the Ray-Ban smart glasses that I found to be very impressive are getting a big AI update starting today. Lives=treaming capabilities are also expanding.

New features are great, but if you couldn’t find a style you liked when the Ray-Ban Meta Smart Glasses launched last October, there's more good news — new styles are on the way too.
Multimodal AI
In our comprehensive list of the best smart glasses to buy in 2024, I mentioned that Meta was testing multimodal input for its Ray-Ban smart glasses. That feature is now rolling out to everyone in the U.S. and Canada.

Read more
Surface Pro 10: all the major changes rumored for the new model
The Surface Pro 9 in laptop mode on a table.

Microsoft has consistently put out a new version of its most popular Surface device, the Surface Pro, and this year we are seeing the Surface Pro 10, the follow-up to the Surface Pro 9 from 2023.

This year's Surface Pro 10 launch is a bit different. We're seeing two models. One aimed at Microsoft's commercial and business users has already been announced. Dubbed the Surface Pro 10 for Business, it mainly keeps the same design, with a bump to Intel Core Ultra CPUs. The other, which is for consumers like you and me, is expected to be announced later with big design changes, and an ARM-based processor instead of an Intel one.

Read more