Humans,however, have only a limited ability to memorize complex, arbitrary secrets, so they often
choose passwords that can be easily guessed. To address the resultant security concerns, online
services have introduced rules in an effort to increase the complexity of these memorized secrets.
The most notable form of these is composition rules, which require the user to choose passwords
constructed using a mix of character types, such as at least one digit, uppercase letter, and
symbol. However, analyses of breached password databases reveal that the benefit of such rules
is not nearly as significant as initially thought, although the impact on usability and
memorability is severe.
。。。 Password length has been found to be a primary factor in characterizing password
strength. Passwords that are too short yield to brute force attacks as
well as to dictionary attacks using words and commonly chosen passwords.