3 ms·
Adversaries will simply use common pass-phrase words as though they were part of a larger alphabet. Depending on the distribution/definition of "common", 2-4 wo
by Gregaros 9y ago
Adversaries will simply use common pass-phrase words as though they were part of a larger alphabet. Depending on the distribution/definition of "common", 2-4 word passphrases are then much worse than an 8 character password, for exactly the reason you state.
- jeremy_wiebe 9y agoAsking because I really don't know: How do they know that a given hash is multi-word passphrase versus average joe's single "word" character jumble? If they flip to using words as part of their alphabet and I'm using 4 unique words, they still have a large search space because the English language has so many more words than the alphabet has letters. So do they just do both? Seems like a huge expansion in computational work.
- Bromskloss 9y agoThey might not know and might have to guess, or do both. This makes it harder for them, but it's hard to quantify how much harder, so it's reasonable to assume the worst case, i.e. that they do know the procedure with which you generated the password.
- Bromskloss 9y agoI'm not sure what point this is meant to counter.