4 ms·
Argh, no! Entropy. It's all about entropy calculation. There is no trick. Look at it this way: - choose 68 bits at random. This is findable by a nation state
by Robin_Message 10y ago
Argh, no!
Entropy. It's all about entropy calculation. There is no trick.
Look at it this way:
- choose 68 bits at random. This is findable by a nation state; if they are your adversary, add a couple more words.
- split those bits into 4 17-bit numbers (17 bits has a maximum of about a hundred thousand)
- your password is 4 words from a hundred thousand word dictionary
- there is no trick: you've encoded 68 random bits securely, and guessing just those bits is pretty impossible.
Schneier is normally sensible but calling entropy a "trick" is idiocy.
- creshal 10y agoOr with actual code: https://github.com/creshal/yspave/blob/master/yspave/pwgen.py https://github.com/creshal/yspave/blob/master/yspave/pwgen.p... A password generator does not care whether its input alphabet is \d, \w, all emoji codepoints, or `cat /usr/share/dict/words`. You determine the entropy of it, and then output as many tokens as needed. It doesn't matter whether an attacker has a copy of your input alphabet, or knows your algorithm. You defeat him by setting the entropy bar high enough (and using a cryptographically secure RNG to generate it). But a random selection of /usr/share/dict/words (~120,000 entries on Arch Linux) will be easier to memorize than a random selection of the ascii printable range.