Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Calm the hell down mate.

The facts are this:

1. Dictionary attacks are generally used before brute force attacks

2. Random passwords can't be cracked via dictionary attacks

This is why I will always prefer random passwords. However I was never disputing that passphrases aren't secure either (in fact I actually said they are), just that I've seen people misinterprete that comic to mean that grouping a couple of obvious words together is more secure than random chars. My point was to illustrate how much more complicated password security is. And this argument where you've gone round in circles trying to argue your silly points actually emphasises that. (And I say 'silly' because half the time you're kicking off over comments that you've misunderstood / misinterpreted).



FACEPALM

Added later:

Yes, dictionary attacks are more common. A dictionary attack is what converts this type of password from lg(27 ^ number of chars) bits, down to lg(wordlist size ^ number of words) bits. There's no way dictionary attacks can be used more effectively than that. Which is to say, the comic itself takes dictionary attacks into account and this kind of password (uniform distribution over words) cannot be cracked by a dictionary attack any easier than a "random" password (uniform distribution over strings) with the same amount of entropy, while being far, far more memorable.


We're going round in circles here because you keep pushing the same argument that was never even disputed and not listening to anything I've had to say on the matter. So I think it's you who deserve the facepalm.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: