4 ms·
First question: If the size of the (known) dictionary is n words and the number of words in your passphrase is k, and if the choice of each word is made by a ra
by JohnStrange 9y ago
First question: If the size of the (known) dictionary is n words and the number of words in your passphrase is k, and if the choice of each word is made by a random number generator, then the entropy of the passphrase is k x log2(n). So for example a passphrase with 8 words from a dictionary containing 200,000 words has entropy 8 x log2(200000)=140.9 bits, which is very secure.
If you don't choose the words randomly, the security may decrease drastically, but I doubt it will be less for a passphrase of 8 words than a non-randomly chosen short 'password'. Generally, XKCD's advice is sound, as long as people are aware that dedicated attackers can and probably will guess common phrases and book codes (passages from a book).
Second question: Yes, any restrictions on password length or allowed characters drastically reduces password security. For example, 8 characters of random Latin1 is too short, it only has an entropy of 56.87 bit. Things get way worse once passords are not randomly generated. A user-chosen password limited to 8 characters of Latin1 is ridiculous and anyone can crack it.
Generally speaking, humanly generated passphrases are no longer secure.