3 ms·
I'm not quit convinced about that. 1) Aren't there people using generators like Diceware that don't do the password management part? 2) The industry's definit
by level3 10y ago
I'm not quit convinced about that.
1) Aren't there people using generators like Diceware that don't do the password management part?
2) The industry's definition of "high security" is constantly changing. Password strength measurement makes assumptions about what is and isn't guessable, and a lot of that depends on what techniques the common brute-force crackers are employing. So finding the right heuristic is also problematic.
- morgante 10y ago> 1) Aren't there people using generators like Diceware that don't do the password management part? I'm not sure they're actually that common. Moreover, if someone is sophisticated enough to use a password generator I assume they have some sort of system for ensuring integrity. Also, if you're worried about someone changing their password to something they don't know, simply force a relogin and have effective password reset mechanisms. > 2) The industry's definition of "high security" is constantly changing. Industry might be getting more serious about encouraging higher security passwords, but standards for high security passwords haven't really changed much. People are just becoming less tolerant of low-security ones. In terms of estimating security, you can use something like https://github.com/dropbox/zxcvbn https://github.com/dropbox/zxcvbn which does a pretty good job of evaluating entropy and resistance to brute force attacks. Ultimately, a password with sufficient entropy will be resistant to any brute force cracker.
- Dylan16807 10y agoThe nice thing about password generators is that you can have a huge margin of strength for free. Keepass defaults to 119 bit passwords. Require 100 estimated bits and you'll blow manual passwords out of the water.