4 ms·
Password strength is: Unknown entropy - known entropy = password strength Where "unknown" entropy is known only to the user and service and "known" entr
by Zamicol 4y ago
Password strength is:
Unknown entropy - known entropy = password strength
Where "unknown" entropy is known only to the user and service and "known" entropy is any entropy known by a third party. Since this is an information problem, it should be treated with the tools of information theory, where security is measured by "unknown" entropy. Services have no way to know if a provided string is entropic, since it may be 100% "known" by others. The only way for a service to verify that a password is secure is for the password to include entropy provided by the service. If the user also wanted to validate entropy, it too could provide entropy for mixing in.
This is just a special case of Kolmogorov complexity, and the highest algorithmic entropy for this problem is a random number.
- water-your-self 4y ago3 //chosen by dice roll
- Tildey 4y ago“Your assigned password will be two random words and 2 random numbers” “Pass”, “word”, “12”, “34”
- Dylan16807 4y agoIt's worth getting a list of the most common passwords and rejecting them, regardless of whether the passwords are generated by machine or by the user. For four digit numbers there's barely any variation in what people use. Even 1234, the most common, is only twice as likely as hundreds of other PINs. Maybe block the top half a percent of most-guessed pins.
- quickthrower2 4y agoSome banks so this: you need an id (not your account number), a password you chose and a code the bank gave you when you signed up