4 ms·
> we have increased the minimum password length to 48 characters. Isn't this complete overkill? I suppose this effectively mandates the use of a password manag
by dblitt 4y ago
> we have increased the minimum password length to 48 characters.
Isn't this complete overkill? I suppose this effectively mandates the use of a password manager, but I wonder where the 48 number came from.
- avereveard 4y agoUgh I use it on my android TV 48 character password would kill my use case
- lapinot 4y agoWell, standard policy for cryptographic keys is to have 256 bits of entropy, with the paranoid number being 512. So if they're using ascii-printable characters, uniform random 48-char passwords have ~315 bits of entropy. That doesn't seem too far off. Basically this means you don't have to trust your key derivation function as much.
- mr_mitm 4y agoAre 512 bit encryption keys even a thing? I thought 256 bits is already for the paranoid, with AES128 being sufficiently secure until quantum computation becomes feasible. I don't even know a symmetric cipher that uses 512 bit keys. Also, since we are talking about hash functions, keys don't even enter the discussion. Hashing is about making password guessing difficult. The length alone doesn't determine how difficult it is anyway, since there are 48 character passwords in popular wordlists. Just enforce 2fa, use argon2 or similar with a minimum password length of 12 and call it a day.
- lapinot 4y agoAh right, i got confused between hash function sizes and cipher key sizes. It's 128-256.