←back to thread

430 points tambourine_man | 1 comments | | HN request time: 0s | source
Show context
raverbashing ◴[] No.41878878[source]
Looks like a good design

Doing something like randomly sampling a range of a-zA-Z0-9 and all the symbols without order or structure is absolutely the worse way of doing it for passwords that humans need to type/read, or in fact anything that might get tripped by special characters (like shell scripts, etc)

Yes yes you might lose a bit of entropy, just add one or two characters to it and it will make up for it. Passwords are not so much bruteforced from zero anymore rather than leaked from places with bad password hashes

replies(1): >>41878971 #
tuxone ◴[] No.41878971[source]
I just opened the Password app for the first time to look at the generator. It seems like the pattern is: [a-zA-Z0-9]{6}\-[a-zA-Z0-9]{6}\-[a-zA-Z0-9]{6} with exactly only one uppercase char and one digit. I don't want to do the maths but that looks like a lot of removed entropy.
replies(2): >>41878985 #>>41879126 #
timabdulla ◴[] No.41878985[source]
He mentions the entropy in the article...
replies(2): >>41879073 #>>41879104 #
tuxone ◴[] No.41879073[source]
Right, thanks. So from 160 bits down to 70 bits of entropy (there is also fancy syllables and bad words to take into account).
replies(2): >>41879109 #>>41879157 #
1. ◴[] No.41879157[source]