2 ms·
Because they're not actually effective. Most brute forcing is done via dictionary attacks.
by memmcgee 9y ago
Because they're not actually effective. Most brute forcing is done via dictionary attacks.
- SomeStupidPoint 9y ago"Dictionary attacks" aren't a magic spell. They're a form of brute forcing, as you seem to be aware. If you're using about 8000 words, randomly chosen, then a 4 word passphrase is about the same as an 8 character random password. (And in fact, for 8k words, it's basically a direct substitution between 2 characters and 1 word.) For most intents and purposes, 8-10 characters is fine, and 20 characters is enough to use as a cryptographic key. Similarly, 4-5 words is fine for most uses, and 10 words is enough to use as a cryptographic key. So I'm not sure what you think isn't effective about passphrases -- they're just using a 2^13 sized alphabet instead of a 2^6.5 one, but either is capable of being used to write down a random string of bits.