5 ms·
@cperciva: Thanks for this; now i'll convert my 8char ascii system password to a 10char one. Do you have any data showing how large a password needs to be to ma
by imajes 15y ago
@cperciva: Thanks for this; now i'll convert my 8char ascii system password to a 10char one. Do you have any data showing how large a password needs to be to make it ridiculously expensive for a TLA (gency) to commit a large amount of hardware to cracking? i.e. how much time past the 10chars does it consume ?
- cperciva 15y agoIt depends on your KDF. MD5 is ridiculously weak; the standard MD5-crypt is 1000 times stronger; bcrypt is better yet; and scrypt is vastly stronger. The best source for this my scrypt paper, really.
- dchest 15y agoLink: http://www.tarsnap.com/scrypt.html http://www.tarsnap.com/scrypt.html
- SoftwareMaven 15y agoWhat license is the scrypt code released under?
- tptacek 15y agoIt's BSD licensed but probably not easy to integrate on your platform. BCrypt is an easier choice. When we see Java and .NET implementations of scrypt, we'll start recommending it, but I'll be honest and tell you that we rarely recommend scrypt today.
- inklesspen 15y agohttp://xkcd.com/538/ http://xkcd.com/538/
- Splines 15y agoTrue enough, if you're targeted it's not going to help very much. However, like outrunning a bear, you only need to be harder to catch than the guy behind you.
- pilom 15y agoI wish I could find a link but,US military spec for secure passwords is 14 characters with capitals and special chars. And they have to be changed every 30 days.