3 ms·
Well, real people won't choose any random 10 characters as a CSPRNG would do. Even when picking words from a dictionary, instead of four words, most people woul
by ericyan 5y ago
Well, real people won't choose any random 10 characters as a CSPRNG would do. Even when picking words from a dictionary, instead of four words, most people would probably just use one (or maybe two). For those are more inclined, they might mess with the capitalisation and sprinkle some numbers to make it "more secure" and adhere to certain password policies. This does not really contribute to the odds as you might expect.
Anyway, the point is, people are terrible at generating (and remembering) secure passwords. By ruling out the default password just means it is not going to be the most insecure one, but the chances of the custom password being secure is still pretty low.
- ascar 5y agoI think most of this comes down to bad education on how to choose a secure password and not an innate inability. And for the most part we software engineers are at fault for advocating and enforcing mostly useless policies for more than two decates. I would love for more websites to implement something like the zxcvbn password strength meter [1], but unfortunately I keep seeing new services or recently refreshed ones using outdated and hurtful policies like requiring numbers and special characters. [1] https://github.com/dropbox/zxcvbn https://github.com/dropbox/zxcvbn