RSS Feed

Gmail password strength check

September 13, 2005 by Saar Drimer

google password strength

I don’t use my gmail account, but I wanted to post something to groups.google and forgot my password. I always put junk in the security question and therefore was sent an email to my “secondary account” with a link to reset the password. All standard stuff.

I entered the desired password and the “password strength” bar told me how “strong” it was. Nice concept that could help some… if it worked, that is. The password “saardrimer” (for an email account saardrimer@gmail.com, mind you) got a “strong” rating as in the image above. “12345678” got “weak”, “jerusalem” got “fair” and “walkinthepark” got “strong” again. I could go on checking more, but I really need some sleep. Some easy guesses and a dictionary attack would easily crack a “strong” one making this feature (as-is) pretty much useless as an indicator for password strength.
In the link explaining how to choose a good password, google explains:

Things to avoid:

* Don’t use a password that is listed as an example of how to pick a good password.
* Don’t use a password that contains personal information (name, birth date, etc.)
* Don’t use words or acronyms that can be found in a dictionary.
* Don’t use keyboard patterns (asdf) or sequential numbers (1234).
* Don’t make your password all numbers, uppercase letters or lowercase letters.
* Don’t use repeating characters (aa11).

(emphasis mine)

They don’t even follow their own rules.

Not a big deal, really, they still have to work on their simplistic checking algorithm; somehow, I expected more from google, though.
I’m just concerned about giving people a false sense of security, when they don’t know better. In these cases, I usually rather they put nothing at all than something weak like this.


6 Comments »

  1. Don’t Tell People What Not To Do!…

    It’s rare to see a substantial usability mistake at Google, and so this jumped out at me. Saar Drimer has a post on the new “Gmail password strength check,” in which he quotes Google’s password advice: Don’t use a password……

  2. Simon says:

    > In these cases, I usually rather they put nothing at all than something weak like this.

    I totally disagree.

    Something that goes some way towards guiding users towards using secure passwords is better than nothing?

    It might not guide all users to a more secure password, but if it guides some proportion of users to a more secure password, that is a Good Thing.

  3. Saar Drimer says:

    Simon,

    There is a danger in training people to bad standards or practices. For example, phishing. For quite some time banks have been sending emails to their customers with links in them. This, in turn, has enabled phishermen to lure these customers into their hooks, so to speak, by embedding links that direct to their own mock web pages to harvest passwords.

    So, while I see your point, I’d rather this feature not be there just for the sake of not giving people the false impression that a bad (or a slightly less bad) choice of password is actually a good one.

  4. Jetman says:

    Hi, men!
    I found another two password strength checkers. Their algorithm based on words dictionary. Try one at microsoft.com – http://www.microsoft.com/protect/yourself/password/checker.mspx and one at itsimpl.com – http://www.itsimpl.com
    Jetman.

  5. boobs tumblr says:

    If you wish for to grow your experience simply
    keep visiting this site and be updated with the newest news
    posted here.

  6. Poulter says:

    com

Leave a Reply

Your email address will not be published.