The Password Haystack Concept in 150 Seconds Los Angeles' KABC-TV produced a terrific & succinct twoand a half minute explanation of the Password Haystacksconcept: Click this link to view their quick introduction. If “123456” is the first password that's guessed, that wouldn't take 18.52 minutes. This calculator is designed to help users understand how many passwords can be created from different combinations of character sets (lowercase only, mixed case, with or without digits and special characters, etc.) and password lengths. But wouldn't something like “D0g” be in a dictionary, even with the 'o' being a zero? But that doesn't matter, because the attacker is totally blind to the way your passwords look. The attacker doesn't know how long the password is, nor anything about what it might look like.

After all searches of common passwords and dictionaries have failed, an attacker must resort to a “brute force” search – ultimately trying every possible combination of letters, numbers and then symbols until the combination you chose, is discovered.

Please see the discussion below for additional information. Yet the Search Space Calculator above shows the time to search for those two passwords online (assuming a very fast online rate of 1,000 guesses per second) as 18.52 minutes and 17.33 centuries respectively!


You may download a shortened, 37-minute, excerpted version presenting the padded password and Haystack calculator concepts: The main concept can be understood by answering this question: Which of the following two passwords is stronger,more secure, and more difficult to crack? If you are mathematically inclined, or if you have some security knowledge and training, you may be familiar with the idea of the “entropy” or the randomness and unpredictability of data. We must always assume that an attacker is as smart as possible (and most are).

