52 ms·
Advice and tactics for passwords have been bad for a long time, perhaps even comically so: https://imgs.xkcd.com/comics/password_strength.png https://imgs.xkcd
by NotAnEconomist 8y ago
Advice and tactics for passwords have been bad for a long time, perhaps even comically so:
https://imgs.xkcd.com/comics/password_strength.png https://imgs.xkcd.com/comics/password_strength.png
- munk-a 8y agoI agree, and a concise response to this article can pretty much be summed up as "Don't roll your own security" for... the fun of it I suppose, I wanted to take a swing at one particularly (IMO) good tear down of why it's stupid for technical reasons, but simply rubber stamping "Don't roll your own security" is pretty acceptable on any of these proposals. This stuff is complicated, if you're a professional at it good on you, it's a tough job, otherwise... just listen to the professionals/best practices and don't feel the urge to be creative, you'll probably break something. It is possible that everyone is wrong, but it's unlikely... and when everyone is wrong (for example Dual_EC_DRBG) if you're using that system it'll be hard not to be aware of the issue when it comes to light.