4 ms·
Well if we're talking about the possibility of an offline attack against a password database that's a bit different. The standards for a good password are highe
by rmtech 8y ago
Well if we're talking about the possibility of an offline attack against a password database that's a bit different. The standards for a good password are higher for that attack.
But anyway if you pick a password from a list of 20 trillion where the offline attacker knows the list, it doesn't actually help them much because a single selection from 20 trillion options has 44 bits of entropy.
Passwords that users choose typically have less entropy than that afaik
- Dylan16807 8y agoMost passwords are worse, yeah, but 44 bits isn't great. With a fast hash that's less than a GPU-week. It's basically enough if you use bcrypt, but even then it's not protected from an attacker with a lot of money to throw at it. (8 GPUs per server, 10 servers per rack, 50 racks, suddenly you're hashing work-factor-10 bcrypt passwords at about 2 million per second and average cracking time is 50 days.)