3 ms·
It's good to see entropy being used as the metric to judge passwords instead of complexity rules. As others have commented, this isn't sufficient though, and w
by efficientsticks 6y ago
It's good to see entropy being used as the metric to judge passwords instead of complexity rules.
As others have commented, this isn't sufficient though, and will over-estimate the complexity of worded passphrases or l33t-speak. Password crackers are wise to those generation techniques and will brute-force combinations of those with more direct generation methods instead of generating from the underlying character set at random.
Complexity rules backfire if the minimum is done to meet them, like capitalise the first letter, append a number 0 and exclamation mark. A tool like this could (and probably should) check for those special cases and discount them from entropy, assuming conservatively that it's a weak password, ie. "P4ssw0rd0!" ~= "p4ssw0rd" ~= "password" ~= 13 bits (a single English word at random).
I'd also add that while that's a cool graph, it's going to age poorly as FLOPs/Watt is still on an upward trend. I wrote a password generator* which takes into account GCloud/AWS GPU prices and wholesale energy costs, along with Hashcat metrics, to recommend the number of bits of entropy for passwords. Looking 20 years into the future you'd probably want something closer to 82 bits entropy than 76, based on my calculations.
* https://github.com/aliclark/pragmatic-password-generator https://github.com/aliclark/pragmatic-password-generator