4 ms·
The second password can fail quite quickly assuming an attacker is going to target Finnish words to perform a dictionary attack, perhaps a Finnish website makes
by CyberRage 5y ago
The second password can fail quite quickly assuming an attacker is going to target Finnish words to perform a dictionary attack, perhaps a Finnish website makes sense for something like this to be done.
Psuedo-random is always better because anything else usually follows a pattern that can be exploited(sequence, structure, words, statistical bias)
If we can't make assumptions about the secret, the only solution is plain brute-force when it comes to the number of characters squared the length of the password.
- Blikkentrekker 5y agoAs I said; it's not a word. It isn't a word and has no actual meaning or morphology; it's comparable to something such as: wrockrangnattentamploozakoshal It conforms to Finnish orthography and phonology, but otherwise not a word.
- CyberRage 5y agoIt seems to be though that it is consisted of some structured elements(I don't know much about Finnish orthography\honology) So if it has some predictable structure, statistical attributes etc, it can be exploited to reduce the search space and therefore can be weaker than the actual raw entropy. Does that matter in the real world? I don't think so.
- Blikkentrekker 5y agoYes it can, so I wonder if the double length offsets that. I would assume that assuming an attacker knows that it is nonce Finnish, that he would be able to craft a specific algorithm that is faster than 32 random character for specifically this, but that in practice if he not know that with all modern approaches it is æquivalent to attempting to bruteforce 32 characters, giving priority to letters and vowels, especially with the inclusion of <ä> and <ö>.
- CyberRage 5y agoAgain, it is hard to compare because I don't know enough about Finnish. the first option is rather simple, assuming we have a good psuedo-random generator with low bias margins. we get: A-Z,a-z,0-9 = 58 options, Length = 16 58^16/2 is the target. Second option is weaker IMO because we know that plain brute-force is rarely being used today for anything over 13~14 characters. We mostly use masks\dictionaries to try common passwords, phrases, sequences. So even if there's a very small chance that someone would have some kind of heuristic rule that targets Finnish orthography\honology, it is still more likely than someone successfully brute-forcing 16 random chars+numbers. Another interesting observation is that fact that it contains common English words by chance. things like rock or tent. those can increase the chance of a dictionary success(our 32 chars starts breaking apart) whereas the 16 chars are random so in nature there are less prone to contain common English words