Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Right idea, but 4 is not enough.

  echidna:~ gwillen$ wc -l /usr/share/dict/words
    235886 /usr/share/dict/words
You get something like 17 bits of password strength per word, depending on the size of your dictionary. (The relevant xkcd estimates more like 11 -- which makes sense because /usr/share/dict/words has a lot of obscure words, shitty words, and alternate forms of words, that you would probably exclude when generating a password.)

So if you want a passphrase that's secure against brute force, you'd want more like 7-12 words.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: