3 ms·
That doesn't matter. I could just put a full stop at the end of the string and call it a complex password. The point of it was for sites that require symbols. T
by libeclipse 10y ago
That doesn't matter. I could just put a full stop at the end of the string and call it a complex password. The point of it was for sites that require symbols. The complex password doesn't add a meaningful amount of entropy to a sufficiently long normal password; a 32 character normal password already has log2(16^32) = 128 bits of entropy.
We rely on the seed for security, the seed being the hash that scrypt spits out
- minitech 10y agoSo it’s way too complicated for that purpose, then.
- libeclipse 10y agoThat's not an argument. Keep in mind that entropy is a property of password generation, not the result of the generation.
- minitech 10y agoI mean, what do you want me to say? It is way too complicated. Why are you using a pre-shuffled character set and getting a permutation of it by index when the index is always extremely low compared to the number of permutations just to get some symbols in your password? Just base64-encode with a custom alphabet or something. I never said anything about entropy, either.