3 ms·
Sure, brute force doesn't online typically, but isn't the reason we have most password requirements generally for the scenario where someone gains offline acces
by strifey 5y ago
Sure, brute force doesn't online typically, but isn't the reason we have most password requirements generally for the scenario where someone gains offline access to password hashes?
- UncleMeat 5y agoSort of. You really don't want to rely on a breach being just the password hashes and nothing else. In the case where the adversary was able to do literally nothing other than exfil the hashes, a stronger password will help you. But is this actually a common threat model? And if you have SMS-2FA enabled, an adversary with your password needs to sim-swap you anyway, which is doable but scales very badly. Easier just to phish people.