4 ms·
True, but (again, as a layman) I don't believe that's the gist of the comic. The artist seems to measure the entropy of the password based on the characters alo
by rtl49 11y ago
True, but (again, as a layman) I don't believe that's the gist of the comic. The artist seems to measure the entropy of the password based on the characters alone. I think a dictionary-based attack would reduce this entropy. I'm happy to be educated about why I'm wrong, though.
- gabemart 11y agoThe entropy count for each word represents picking one word at random from 2^11 choices of words. It doesn't have anything to do with the characters.
- dec0dedab0de 11y agoEspecially since the average vocabulary is closer to 2^14
- Symbiote 11y agoNo, he measures the entropy based on a machine knowing the format. If I roll a dice, and ask you to guess the result, it will take you 3 guesses on average to get the result. If I ask you to guess the random word I've chosen, it will take you around 1000 guesses (if I have a small vocabulary). Entropy is calculated as ln₂(x), where x is the number of possibilities. With four common words from a list of 2000: 4 × ln₂(2000) ~= 44 as used in the comic. If, instead, the password was taken to be 28 random characters from [a-z ], the entropy would be 28 × ln₂(27) ~= 133 This is the overestimate that the artist didn't make. With a genuinely random alphanumeric password, like 0LsW-nT5#^kQ, the entropy is higher: 12 × ln₂(92 keys on the keyboard) ~= 78. but the point of the XKCD was to show a memorable password.