3 ms·
That math is only correct for randomly chosen passphrases, but the rules you criticize are for user-invented passphrases. Even just adding capitalized letters t
by JohnStrange 9y ago
That math is only correct for randomly chosen passphrases, but the rules you criticize are for user-invented passphrases. Even just adding capitalized letters to user-invented passphrases can drastically increase their security.
To be fair, there are good reasons to assume that even long user-invented passphrases are no longer secure enough against offline attacks, especially when the keystretching algorithm is nonstandard or does not even use salt.