4 ms·
A random 20 character password in base 72 is equivalent to a 124 character password in base 2. They have the same amount of security: 124 bits. https://convert
by Zamicol 4y ago
A random 20 character password in base 72 is equivalent to a 124 character password in base 2. They have the same amount of security: 124 bits. https://convert.zamicol.com/#?inAlph=0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz%21%23%24%25%26%28%29%2A%2B-&in=--------------------&outAlph=XY https://convert.zamicol.com/#?inAlph=0123456789ABCDEFGHIJKLM...
If a service didn't want to store 124 _bytes_ in a database to represent the above base 2 password, it can use a hashing algorithm to like SHA256 to reduce the storage requirements to 32 bytes. The password still has 124 _bits_ of entropy even though 256 bits are stored.
>Calculating the number of bits only makes sense if the attacker knows what your character set is.
Assume that the attacker knows the character set in both cases, as this is the worse case scenario. The equivalence is then apparent.
>I don’t know what “strong” really means
Strength in information theory is entropy, and entropy is measured in bits. https://en.wikipedia.org/wiki/Password_strength#Entropy_as_a_measure_of_password_strength https://en.wikipedia.org/wiki/Password_strength#Entropy_as_a...
- janalsncm 4y agoYes, I know that strength is measured in entropy. The question is what the benchmark for a “strong” password is.