3 ms·
This is funny but is the opposite of the idea espoused in the correcthorsebatterystaple xkcd. Welsh words are hard for (most) humans to remember, but easy for m
by krilly 7y ago
This is funny but is the opposite of the idea espoused in the correcthorsebatterystaple xkcd. Welsh words are hard for (most) humans to remember, but easy for machines to check (since wordlists are publicly available)
- deleted 7y ago[deleted]
- half-kh-hacker 7y agoBut surely word lists are publically available for English words too?
- bussierem 7y agoCorrect, but one facet of xkcd passwords is that it's very easy to remember which prevents people from writing down passwords on sticky notes, thus eliminating that security risk. In the case of Welsh words, it's about as easy to remember for a non-Welsh speaker as leetspeak is, and so people will just write down the password somewhere again to remember it, which makes this less secure overall than xkcd passwords on English.
- SAI_Peregrinus 7y agoYes. Diceware is one such, the EFF has some improved variants. With 7776 words you can roll 5 dice and get a number, which becomes a word. log(7776)/log(2) = ~13, so 13 bits of entropy per word chosen. 7 words for 91 bits of entropy (over the 80-bit absolute minimum for decent security of a key), 10 for 130 bits of entropy (better than 128-bits that lots of people use for AES), 20 for 260 bits (better than 256, enough to resist even batch attacks by enormously powerful actors). Of course a 20 random word string is less a "password" or "passphrase" and more a "passpoem". You only want one or two of those, as master passwords for a password manager.