This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Passfault"

From OWASP
Jump to: navigation, search
m (Cleaned up links)
(Classifications)
Line 84: Line 84:
 
   {| width="200" cellpadding="2"
 
   {| width="200" cellpadding="2"
 
   |-
 
   |-
   | align="center" valign="top" width="50%" rowspan="2"| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]
+
   | align="center" valign="top" width="50%" rowspan="2"| [[File:Owasp-labs-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Lab_Projects]]
 
   | align="center" valign="top" width="50%"| [[File:Owasp-builders-small.png|link=]]   
 
   | align="center" valign="top" width="50%"| [[File:Owasp-builders-small.png|link=]]   
 
   |-
 
   |-
Line 93: Line 93:
 
   | colspan="2" align="center"  | [[File:Project_Type_Files_CODE.jpg|link=https://github.com/c-a-m/passfault]]
 
   | colspan="2" align="center"  | [[File:Project_Type_Files_CODE.jpg|link=https://github.com/c-a-m/passfault]]
 
   |}
 
   |}
 
|}
 
  
 
=FAQs=
 
=FAQs=

Revision as of 21:34, 24 February 2015

Passfault-header.png

OWASP Passfault

OWASP Passfault evaluates the strength of passwords accurately enough to predict the time to crack. It makes creating passwords and password policies significantly more intuitive and simple. Passwords don't have to be annoying!


Introduction

OWASP Passfault is more ...

Accurate 
Measures the size of password patterns and identifies more weak passwords, yet allows strong passwords that don't match traditional password policies
Informative 
Provides detailed analysis of the password and sub patterns within the password, so users quickly learn how to make strong passwords without training.
Simple 
Presents the password strength as the "time to crack" to help communicate the risk of poor paswords, providing the incentive to create stronger passwords.
Powerful 
Empowers administrators to know and control the strength and risk of the organization's passwords.


Description

When setting a password, OWASP Passfault examines the password, looking for common patterns. It than measures the size of the patterns and combinations of patterns. The end result is a more academic and accurate measurement of password strength.

When setting a password policy, OWASP Passfault simplifies configuration to one simple meaningful measurement: the number of passwords found in the password patterns. This measurement is made more intuitive and meaningful with an estimated time to crack.


Licensing

OWASP Passfault is free to use. It is licensed under the [Apache License version 2.0] .

What is Passfault?

OWASP Passfault provides:

  • Password Strength Evaluation
  • Password Policy Replacement


Presentation

Passfault-prezi-thumbnail.png

Articles

Your Passwords don't Suck, its your Policies [ZDNet]

Redefining Password Strength and Creation [MidsizeInsider, IBM]

How long would it take to crack your password [Naked Security, Sophos]


Quick Download

[downloads]


Demo Page

[demo site]


Project Leader

Cam Morris


Related Projects


Ohloh


Classifications

Owasp-labs-trans-85.png Owasp-builders-small.png
Owasp-defenders-small.png
Apache-feather-small.gif
Project Type Files CODE.jpg