3 ms·
Just 3 words will not make a safe password. People are asking in comments why, so let me try to offer an explanation. First of all, we don't know how large is
by jacekm 7y ago
Just 3 words will not make a safe password. People are asking in comments why, so let me try to offer an explanation.
First of all, we don't know how large is the dictionary. @Symbiote mentioned 132k words, but typically for diceware method (a method where you randomly select words from a dictionary) only 7776 are used (why so few? because then it's easier to select the words by rolling an actual dice). Nevertheless, let's assume 170k for now. Nowadays you can crack 100-500 GH/s (100*10^9) [1] at home (you need $25000 for the hardware, but let's assume a rich household ;))
So we have (132k^3) / (100 GH/s) = 23000 seconds [2]. That's less than 7 hours!
You could argue that nowadays everyone uses bcrypt, so such speeds are not possible. The question is: are you really sure that no one uses md5 any longer?
[1] https://gist.github.com/epixoip/ace60d09981be09544fdd35005051505 https://gist.github.com/epixoip/ace60d09981be09544fdd3500505...
[2] https://www.wolframalpha.com/input/?i=%28132000%5E3+hashes%29+%2F+%28100+GH%2Fs%29 https://www.wolframalpha.com/input/?i=%28132000%5E3+hashes%2...