4 ms·
Crypto people make fun of me for making up passwords in my head, but my brain RNG has never been exploited, nor has anyone successfully Sherlock'd my password.
by pants2 2mo ago
Crypto people make fun of me for making up passwords in my head, but my brain RNG has never been exploited, nor has anyone successfully Sherlock'd my password.
- angry_octet 2mo agoIf it's long enough it's fine. They key property for passphrases is being able to remember them. But diceware phrases where you actually roll dice are stronger, and has evident verifiability. RNG on computers is still hard, and a proper HSM has a carefully designed source of randomness and mixing. I'd trust Yubikey RNG mixing into Linux urandom much more than a random hardware wallet developer.
- pants2 2mo agoYeah, something very cool is XOR can only improve randomness as long as there's no correlation between the sources. So Linux RNG XOR'd with this comment is even better than it's source!