3 ms·
Why not base64? Even shorter, readable, typable, copy-pastable (why are you copy-pastung passwords?), and pehaps even memorable.
by jsprogrammer 11y ago
Why not base64? Even shorter, readable, typable, copy-pastable (why are you copy-pastung passwords?), and pehaps even memorable.
- falcolas 11y agoIndeed. $ dd if=/dev/random bs=1 count=32 | base64 ca2ktYYvppr1/HwwGYrg01udQX1cP4Ek5VmyzQydT+8=
- yoo1I 11y agoMy mother was a saint!! ... when I just still wet behind the ears I was studying the codebase of my first job, and came across a quite extensive badwords.txt . On asking why we had a the dictionary of cussing in our project, I found out that the randomly generated passwords that we sent to our clients, apparently managed to get a customer quite angry when one of the words produced started with a slur, and this was a filter to prevent that from happening again Generating random passwords isn't quite as straightforward as it would seem to be...
- vog 11y agoThis approach requires that your badwords.txt is not just extensive, but supports all languages. Isn't it easier to just generate words without vowels? This is the more common solution to that problem, IIRC.
- yoo1I 11y agoYeah I thought about that as well when I wrote down the above. Doing general localization is really hard if you want to do it well. If you know your approximate audience, you probably have to tailor your localization to them, instead of everybody. Case in point: Not all scripts even have vowels.
- falcolas 11y ago> randomly generated passwords > we sent to our clients I'm making the assumption that these are one-time passwords for initial account setup. But no, no one scheme will work for everything, obviously. The hex version will fail for schemes which have an upper limit, or when there's a requirement for upper/lower/symbols. The base64 encoding will fail other validations due to the '/' character, or for particularly restrictive upper size limits. I wish all of them would simply accept a string and put in an upper limit of 1k to limit DOS by password. Call it good.
- sbierwagen 11y agoThat would fail if you tried using it as a password with JetBlue, which does not allow the letters Q or Z: http://security.stackexchange.com/questions/57909/why-would-you-not-permit-q-or-z-in-passwords http://security.stackexchange.com/questions/57909/why-would-...
- falcolas 11y agoAnd the hex encoding fails if they require a symbol. No single passphrase generation tool works for all sites... but that's more a problem with the sites' requirements for passwords.
- deleted 11y ago[deleted]
- sp332 11y agoI copy-paste passwords from a password manager. Usually it puts it right in the clipboard for me though, so I don't have to highlight it manually.