Anton Dedov tested several popular password meters to evaluate their security effectiveness and user-friendliness. He found that passwdqc and zxcvbn were most balanced, blocking common attacks while still accepting passwords users find intuitive. All meters protected against online attacks, and likely offline attacks with slow hashes and unique salts. However, most denied more passwords than necessary, including strong, uncommon passwords. Larger dictionaries and real user studies could provide more insights. Special thanks were given to security experts who advance password protection.
Related topics: