3 ms·
That argument baffled me as well. Using the 'dictionary size' defined by the distinct set of characters as an input for the entropy calculation seems absurd, un
by cmenge 10y ago
That argument baffled me as well. Using the 'dictionary size' defined by the distinct set of characters as an input for the entropy calculation seems absurd, unless the attacker has a way to know the dictionary, for instance because they know a login can be made using a numeric keypad alone.
Also, with that definition, a password 'abcde' would have much higher "entropy" than 'aabab', meaning that this measure penalizes actual randomness, where repetition and char-reuse are very likely.