RE: TGP Password Strength Checker online

"Thor (Hammer of God)" <[email protected]> Thu, 15 Jul 2010 16:12:56 +0000
Newsgroups gmane.comp.security.microsoft
Message-ID <[email protected]>
> On 2010-07-13 Thor (Hammer of God) wrote:
> > I've been thinking about standing up the Password Strength Checker
> > tool in TGP online, so here it is:
> >
> > https://www.hammerofgod.com/passwordcheck.aspx
> 
> Please do *not* encourage people to enter their passwords on random
> websites. It was already a bad idea when Microsoft did this, and unlike good
> Whisky, the idea didn't get better with time.

I do not encourage people to enter their passwords on random websites.  I do, however, encourage people to read PDDs (Prominently Displayed Disclaimers) that state:
"This is implemented in server-side code, which means that when you type, the phrase you are testing is sent across the Internet.  I do not store or track (or care) what passwords you test.   If you are really worried about it, then don't use real passwords.  In fact, I recommend that you *don't* use real passwords.  There's no reason to risk it.  Note that this page supports HTTPS."

t