4 ms·
If I read the paper correctly: They trained a state-of-the-art password guessing NN. They used this to train a second NN to estimate the number of guesses need
by vimax 6y ago
If I read the paper correctly: They trained a state-of-the-art password guessing NN. They used this to train a second NN to estimate the number of guesses needed by the first NN to guess a given password, and used this second NN as the password meter.
A password is resistant to online attacks if it takes more than 10^6 guesses, and resistant to offline if it takes more than 10^14 guesses.
After comparing combinations of password requirements, blocklists, and strength requirements, they found that minimum of 12 characters, and a NN estimate of more than 10^12 guesses is the best password requirements for usability and protection from offline attacks.
So instead of heuristics for a strong password, they derive the strengths from how many attempts it would take a SotA NN to guess the password.