3 ms·
Does the password strategy really just truncate passwords over 64 characters? I don't use them often but since text passwords typically have low number of signi
by bondolo 5y ago
Does the password strategy really just truncate passwords over 64 characters? I don't use them often but since text passwords typically have low number of significant bits per character I have always assumed that the input string was hashed to a fixed length password that would increase in quality until the randomness of the text approached random bytes. My current secure passphrase is a paragraph that I have memorized from a book, about 250 characters, but I only type it a couple of times per month. Disappointing if 190 or so characters of this typing is indeed wasted effort and that at least 8 bytes or more (1-3 bits per character) of entropy is wasted per password because text doesn't use all 8 bits.