4 ms·
Although by chance you might pick a good password, you have absolutely no guarantee of the strength unless its generated from a distribution with known entropy.
by Straw 6y ago
Although by chance you might pick a good password, you have absolutely no guarantee of the strength unless its generated from a distribution with known entropy. The problem with assuming any particular distribution for the attackers is that they tend to constantly update their attacks as password trends evolve.
Random password, picked uniformly from strings up to 1000 characters? Almost certainly at least 900 characters, extremely strong. Probability of picking "password"? Less than the probability you're currently hallucinating, or that there's a bug in your code, or that an attacker guesses your password by pure chance.
You can't show that particular string isn't easy to guess- perhaps it follows a common pattern of humans spamming "random" keypresses with far lower entropy than one would expect. Can I show that I could guess something without seeing it beforehand? Probably not. Don't settle for "I couldn't guess this password" when you can get "No one can guess this password".