4 ms·
Better than nothing, but that's still easily brute-forcible, even by humans.
by kgo 16y ago
Better than nothing, but that's still easily brute-forcible, even by humans.
- lukeschlather 16y agoNo, it's not. I ran across one where apparently I had chosen "favorite restaurant" 10 years ago. I tried 5 likely candidates, and several passwords I use for these things. Nothing went.
- kgo 16y agoBut if even you can't guess the right answer, then that doesn't really count, does it? Hacker can't get access to your account, but neither can you. Might as well have entered sdaw4#$%@#$%#$5. I'm talking about the scenario where someone either has your answer from another corrupted site, or tracks down the information publicly, like the kid who 'hacked' Palin's email. Assuming you're using legit info, it's easy enough to try several reasonable variations of, say, University of Iowa, in the way a human would abbreviate it.
- tomkarlo 16y agoI think you're missing my point... these are very occasionally used passphrases that really aren't as easy to remember as one might think. At the same time as the article points out, they're easier than an random password to hack. So worst of all worlds: harder to remember, easier to break.