1Password password quality algorithm
Is the algorithm by which 1P decides if a password is poor -> excellent with respect to “quality” public?
There are so many competing algorithms on password quality, but few are by makers of outstanding security tools like 1P.
I’m part of an “uplift” project for my users and whilst we regularly recommend 1P for use, we can’t mandate it - so at the very least we want our own password quality meter to align with 1Password to keep things consistent.
Wasn’t sure where to ask this, but as a Mac user was hoping someone from Agile Bits would chime in.
Comments
-
Hey @doetraar:
This is a great question, and I'm glad to hear you want to use us as a guide to help your team improve your password security, even if you aren't using 1Password to store all your credentials. 😀
1Password calculates password strength for passwords that have been manually entered into 1Password using a two step process. First 1Password uses zxcvbn to calculate the order of magnitude of the number of estimated guesses it would take to crack that password (
result.guesses_log10
). We then map that result to our score, which is a 1-100 value, with higher being a stronger password.Jack
0