5 ms·
My own password generator simply uses /usr/share/dict/words On my system /usr/share/dict/words has ~45k words. That's 15 bits of entropy per word, significantl
by omh 11y ago
My own password generator simply uses /usr/share/dict/words
On my system /usr/share/dict/words has ~45k words.
That's 15 bits of entropy per word, significantly more than XKCD (which assumes 11 bits).
So I'd agree that there probably aren't many unique dictionaries.
The strength of this password scheme is that it works even assuming the attacker knows your dictionary.
In practice, I guess that an attacker will use a concatenation of all popular dictionaries. This will make things slightly harder for them (e.g. if they have 50k words vs the 30k in your dictionary) but not by a huge factor.
- creshal 11y ago> The strength of this password scheme is that it works even assuming the attacker knows your dictionary. Indeed. Arguing about whether or not your dictionary is "unique" enough is a red herring. Whatever generator you use should accounts for the dictionary's word entropy, not for the theoretical per-byte entropy.