Random password guesses result in account lockout after a limited number of incorrect attempts. “Yes” because complex passwords prevent a hacker from guessing your password either across the network or locally on a system. The question is, “Is all that complexity enough to protect us from hackers?” The answer, to further complicate matters, is “Yes” and “No.” And, we’re discouraged from using the same password for every account.
Password policies designed by well-meaning system administrators dictate the required number of characters and the complexity of passwords, but is that dictated complexity enough to protect user accounts from hackers? We’re told to create passwords that are “easy to remember but hard to guess.” We’re instructed to choose passwords that contain upper- and lowercase letters, that include numbers, and that have a few alternative characters as well.