4 ms·
Yes, it really is more secure than exact re-use. Attackers that just try the exact same password on multiple sites on first discovery will be thwarted by algori
by jpfed 9y ago
Yes, it really is more secure than exact re-use. Attackers that just try the exact same password on multiple sites on first discovery will be thwarted by algorithmically derived passwords.
I'm not ruling out that there will be attackers that try to harvest passwords from multiple sites, join those sites by username or email, then try some ML to derive people's password algorithms. But there is a whole class of attackers that just won't bother with that level of sophistication.
If your algorithm is any good, you're already not the slowest person running from the bear (cf. easy passwords or exact-password-reuse).
- donald123 9y agoHaving less hackers or taking hackers a little more effort to crack the password do not make it more secure in any ways. This is security through obscurity. Do you think the hackers will stop like a bear when they crack the first password? If password can be cracked, they are insecure, no matter it takes the hacker 10 minutes or 10 hours. And it does not take ML to derive these simple algorithms at all. People may think their password algorithm is good, but it lacks the fundamentals of cryptography. It's really just a puzzle you play with the attacker.