4 ms·
According to KeePass2, the password: "12" contains 7 bits of entropy, but "1234" only contains 5 bits of entropy. Is that right?
by mfoy_ 7y ago
According to KeePass2, the password: "12" contains 7 bits of entropy, but "1234" only contains 5 bits of entropy.
Is that right?
- gruez 7y agoI wouldn't trust it. If you use the "Hex key - 128-bit" preset, it returns a different amount of bits every time you click it. Here are 3 samples: 3f38ba8a6ce3aa800f007c2e431df7fd 124 bits 9339bf587ee11b12d207df846a879cf4 129 bits 8ca4354a9038df590fecec1f964062fd 121 bits
- heeen2 7y agoDue to missing or repeated characters from the set of the hex alphabet?
- gruez 7y agowhich doesn't make sense. I randomly generated an 8 character alphabetical (all lower case) password "jraxxhwr". According to keepass it has 32 bits of entropy, but the entropy should be 26^8 = 37.6 bits because the search space is all 8 character letter permutations. There's no way you can reduce the search space from 37.6 bits to 32 bits unless you have an oracle that says which characters I used.
- FabHK 7y agoIt does make sense, because the keepass entropy estimate presumably (like the excellent zxcvbn) tries to approximate the empirical distribution, not the theoretical uniform one. In theory, "68703649" and "12345678" are equally likely to be pulled from the hat, but in practice one is a much better password than the other. You can reduce the search space by trying the passwords with higher (empirical) probability first.
- DCoder 7y ago> the keepass entropy estimate presumably […] tries KeePass sources are available [0], you can see the specific algorithms it uses in [1]. [0]: https://sourceforge.net/projects/keepass/files/KeePass%202.x/2.42.1/ https://sourceforge.net/projects/keepass/files/KeePass%202.x... [1]: https://fossies.org/windows/misc/KeePass-2.42.1-Source.zip/KeePassLib/Cryptography/QualityEstimation.cs https://fossies.org/windows/misc/KeePass-2.42.1-Source.zip/K...
- FabHK 7y agoThanks. I've looked at the code, and it does not seem to try to estimate the empirical distribution (doesn't appear to be using dictionaries, for examples). Then the discrepancy maybe comes from the number of glyphs within certain categories, or their repetition?