3 ms·
I agree that machine-generated passwords are better, though it spends half of the article on it, based on this weird statement: > The LastPass account password
by etse 4y ago
I agree that machine-generated passwords are better, though it spends half of the article on it, based on this weird statement:
> The LastPass account password “best practices” advice linked to in their announcement says nothing about using a password generator, so it would be incorrect to assume that users are generating their LastPass passwords using a strong password generator.
A more compelling criticism would be to identify some flaw in the UX instead of the absence of something in documentation, which is a really poor signal for user behavior.
- secabeen 4y agoThey also give zero justification or explanation for why they selected 2^36 as the complexity that is assumed for the reader's password. It's too bad, as their own page on PBKDF2 (https://support.1password.com/pbkdf2/ https://support.1password.com/pbkdf2/) shows what the complexity and cost is of various password models, but they don't use any of that data, and just stick with the $100 / 36 bits number. Based on their own page, I would probably estimate the complexity of the average user's password at around 50 bits (3 word, digit separator, capitalize one), but that would result in a $1 million dollar crack cost, largely wiping out their own argument.