LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-06-2013, 02:59 AM   #1
linustalman
LQ Guru
 
Registered: Mar 2010
Location: Ireland
Distribution: Debian 12 Bookworm
Posts: 5,726

Rep: Reputation: 479Reputation: 479Reputation: 479Reputation: 479Reputation: 479
Question Offline Password Strength Checker


Hi.

I'm looking for an offline password strength checker. Similar to how this website works: http://www.passwordmeter.com

I've tried this on KeePassX but it wont allow me to paste long passwords in for some reason. [image attached]
Attached Thumbnails
Click image for larger version

Name:	KeePassX - custon pw.gif
Views:	175
Size:	19.1 KB
ID:	12867  

Last edited by linustalman; 07-06-2013 at 03:02 PM.
 
Old 07-06-2013, 02:45 PM   #2
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,671
Blog Entries: 4

Rep: Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945
In my humble, no password can be considered to be "strong." Let's face it: it's either going to be written-down on a piece of paper taped underneath the keyboard, or it's going to be added to the list of saved-passwords in a web browser ... from whence it can be filched.

In my humble, the only plausible way to enforce security is by the use of digital certificates that are individually issued ... disallowing the use of passwords.

Think about it: when you enter any office building, you must swipe your badge. No one's sitting there saying, "say the magic word."
 
Old 07-06-2013, 03:49 PM   #3
273
LQ Addict
 
Registered: Dec 2011
Location: UK
Distribution: Debian Sid AMD64, Raspbian Wheezy, various VMs
Posts: 7,680

Rep: Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373Reputation: 2373
What's wrong with writing down a password though? If it's at home then you can leave it next to the computer unless you're encrypting your hard drives and you think a burglar will do some hacking. If it's a work password then a slip of paper in your wallet or purse can be used until you remember it properly -- if somebody steals your wallet or purse then they're hardly likely to then run to your place of work and try to log into your PC.
Sure, certificates are nice but they end up being protected by passwords ultimately since anybody stealing your token can gain access -- in the same way car thieves often break in an steal car keys to make theft easier. certificates stored on hardware like smart cards can be a pain if you forget the also -- as a colleague of mine found out the other day.
There is no panacea just lots of ways to make things more difficult for anybody trying to gain unauthorised access.

As to the original question I am sure that at least one of the password check sites allows the downloading of the web page for offline use but I can't seem to find it now, sorry.

Last edited by 273; 07-06-2013 at 03:52 PM.
 
Old 07-06-2013, 09:25 PM   #4
weirdwolf
Member
 
Registered: Jun 2007
Location: 1 AU from a G2V star
Distribution: PCLinuxOS LXDE / Android
Posts: 247

Rep: Reputation: 434Reputation: 434Reputation: 434Reputation: 434Reputation: 434
Something like this ?
https://www.grc.com/haystack.htm
 
Old 07-06-2013, 11:01 PM   #5
m.a.l.'s pa
Member
 
Registered: Oct 2007
Location: albuquerque
Distribution: Debian, Arch, Kubuntu
Posts: 366

Rep: Reputation: 139Reputation: 139
Quote:
Originally Posted by weirdwolf View Post
Something like this ?
https://www.grc.com/haystack.htm
Excellent. Not exactly what the OP asked for, but if you read through the info on the page, what's being said there seems to eliminate any need for an offline password strength checker.
 
Old 07-08-2013, 09:03 AM   #6
David Trest
Member
 
Registered: Jul 2013
Distribution: CentOS/RHEL, Backtrack, many more.
Posts: 58

Rep: Reputation: Disabled
Quote:
Originally Posted by sundialsvcs View Post
In my humble, no password can be considered to be "strong." Let's face it: it's either going to be written-down on a piece of paper taped underneath the keyboard, or it's going to be added to the list of saved-passwords in a web browser ... from whence it can be filched.

In my humble, the only plausible way to enforce security is by the use of digital certificates that are individually issued ... disallowing the use of passwords.

Think about it: when you enter any office building, you must swipe your badge. No one's sitting there saying, "say the magic word."
You are correct. And no matter how secure/encrypted you make your password, someone can just beat it out of you (a la XKCD). That's why two-stage auth is far better, using something you know (a password, for example) and either something you have (keyfob, token, smartcard, etc.) or something you are (fingerprint, retinal scanner, voice recognition, etc.).
 
Old 07-08-2013, 09:58 AM   #7
jpollard
Senior Member
 
Registered: Dec 2012
Location: Washington DC area
Distribution: Fedora, CentOS, Slackware
Posts: 4,912

Rep: Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513Reputation: 1513
Quote:
Originally Posted by sundialsvcs View Post
In my humble, no password can be considered to be "strong." Let's face it: it's either going to be written-down on a piece of paper taped underneath the keyboard, or it's going to be added to the list of saved-passwords in a web browser ... from whence it can be filched.

In my humble, the only plausible way to enforce security is by the use of digital certificates that are individually issued ... disallowing the use of passwords.

Think about it: when you enter any office building, you must swipe your badge. No one's sitting there saying, "say the magic word."
Actually, the building swipe reader is saying just that.

Anyone with a copy of the magnetic stripe on your card has the password.... Now CAC cards are not a swipe - but even they can be spoofed (I have captured the password during testing... so they aren't all that secure either).

Last edited by jpollard; 07-08-2013 at 09:59 AM. Reason: typos
 
  


Reply

Tags
check, offline, password



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Password strength Suse 11 karlochacon Linux - Newbie 1 06-17-2013 12:01 PM
How to test password strength codergeek General 21 02-08-2013 10:20 PM
password strength abhi_mattur Linux - Security 5 02-01-2008 01:34 PM
simple password checker CarryD Programming 1 09-02-2006 07:37 AM
Help using Crack for testing password strength dai Linux - Security 2 07-02-2003 03:34 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration