3 ms·
Would you be happy if a service you used encrypted your private data with 56-bit DES encryption? Because that is basically what you are saying. If a password is
by nmadden 4y ago
Would you be happy if a service you used encrypted your private data with 56-bit DES encryption? Because that is basically what you are saying. If a password is estimated to have 40 bits of entropy on average (as per Wikipedia), then adding 18 bits of protection takes it to 58 bits. Two decades ago we were able to crack DES keys in less than 24 hours: https://en.wikipedia.org/wiki/DES_Challenges https://en.wikipedia.org/wiki/DES_Challenges
- dale_glass 4y agoIt still helps if you're not actually using passwords. I use a Mooltipass (https://www.themooltipass.com/ https://www.themooltipass.com/) loaded with keys generated with pwgen -s 16 (fully random, alphanumeric, 16 chars) That seems to give about 95 bits per password, plus 18 brings it up to 113, which I think is not bad at all. I'm pretty sure I can count on my passwords not ever being cracked by brute force. Anybody stealing a password database will have time and effort constraints, and will likely be happy with just cracking the easier set. If a government wants my stuff it's much easier to just convince the service provider to give them the data directly.
- nmadden 4y agoIf you’re not actually remembering these passwords and you want to increase security from 95 to 113 bits, then it is much more efficient to simply add a few more characters to the password. pwgen -s 19 provides the same extra protection as 300,000+ iterations of PBKDF2.