[QUOTE=sdguy]
I worked at a place once where we had a similar thing, if you tried three times and failed it locked you out and you had to go to the computer guy to have him reset it. And it was sad on days when he wasn’t there because you couldn’t get in to your email at all.
I just wondering why everyone doesn’t limit the number of times you can try each day. It would seem to stop most dictionary type attacks.
[/QUOTE]
One other note is that this is a very poor solution.
Dictionary words are bad not because they can all be scanned, but because that limits the number of combinations. With six characters, combining letters and numbers, plus uppercase and lowercase you have 6[sup]46[/sup] possible passwords (which appears to be a 36 digit, very large number.)
For a password like this, you can give a user thousands of free tries without worry that the password will be cracked.
With a dictionary word (which will fairly invariably be in all lowercase, probably between 4 to 8 characters, and a relatively common word), you’ve got maybe…50,000 or so words that might be used. Now if I fail you if you mess up three times, that means that I’ve got a 3 in 50,000 shot of guessing your password, but I don’t want to try 3 times since that sets off alarms, so instead I try one each day. So this means that I’ve got a 365 in 50,000 chance of guessing your password in a year, or rather a 1 in 136 chance.
At a 1 in 136 chance, if I’m attacking something like the Straight Dope, where I can pick up all the usernames as a guest, this means that I can attack several thousand people a day. Over the course of a year I’ll have figured out the password of hundreds of Dopers, and no one will be the wiser.
Any password worth protecting should be secure enough that you can give a regular user hundreds of tries in a day and still not have any worry of passwords getting cracked.