2 ms·
I do like this answer, but I'll also point out that making someone guess two strings is just as secure as making them guess one long string. If root has a rando
by goldmab 16y ago
I do like this answer, but I'll also point out that making someone guess two strings is just as secure as making them guess one long string. If root has a random 10-char password, that's roughly the same number of guesses as a user's first name with an 8-char password.
- Peaker 16y agoUnless they can read the shadow file somehow, or a specific user attack vector makes it somewhat easier than complete guessing...