3 ms·
Number of iterations being discussed is how many times the password is hashed. It is a setting the system chooses and is independent of the password length the
by azeemba 4y ago
Number of iterations being discussed is how many times the password is hashed. It is a setting the system chooses and is independent of the password length the user chooses.
If you are asking if the length of the password by itself be sufficient to create a secure password, then the answer is mostly no. You need many iterations of the hashing process otherwise brute force attacks become trivial given today's hardware.
- Aeolun 4y agoA sufficiently difficult password is unguessable even with a single hash.
- SAI_Peregrinus 4y agoUnless you have a high-entropy long password. 10 Diceware words (words chosen uniformly at random from a list of 7776 words) is over 128 bits of entropy, even a very fast hash would be enough for such a passphrase. Of course at that point you've essentially memorized a cryptographic key, not a traditional low-security password. Good for the master password of a password database, not so usable anywhere else.
- runnerup 4y agoI'm not super practiced in hashing theory. If the 10 words were usually longer than the hash function output (say, starting at an average of 7 words), would adding more characters (words) still increase the entropy or would the entropy get truncated?
- aidenn0 4y agoIt will theoretically increase the entropy until the total entropy exceeds the length of the hash (not the total length of the input). What we really care about is how hard it is to determine the passphrase given the hash. With a 128 bit hash, an attacker requires an average of 2^127 guesses if they are guessing completely randomly. So as long as your passphrase is well before the first 2^128 guesses an attacker is likely to make, making it harder to guess is theoretically useful. For example, "AAAAAAAAAAAAAAAAAAAAAAAAAAA" has more than 128 bits, but it's also going to be (relatively) easy to guess. As shorthand we say "it has less than 128 bits of entropy" In the example that GP gave, you could advertise "I used 10 diceware words for my passphrase" and it would still be as hard for the attacker as attacking a 128 bit hash. 7 diceware words would be much longer than 128 bits, but if you advertised "I used 7 diceware words" it would give the attacker a significant advantage, since there are much less than 2^128 possibilities.
- e12e 4y agoAgreed - but note that 7 diceware words is still 90 bits of entropy - much less than 128, but still a pretty good password!