3 ms·
I agree there is nothing technically bad about using usernames as more entropy (it is bad from a user experience standpoint), but why have two strings at all? J
by nathantotten 8y ago
I agree there is nothing technically bad about using usernames as more entropy (it is bad from a user experience standpoint), but why have two strings at all? Just have one longer, truely random string.
> Because having an unknown username with an unknown password increases the difficulty of compromise via improved entropy.
Not necessary. It depends on the characteristics of each. If the username is truely random, sure, but then you are back in the same boat as using one random string.