3 ms·
An attacker might be looking over your shoulder, and see the first characters of your password. Or he might read HN, and see that your preferred passphrase met
by beala 14y ago
An attacker might be looking over your shoulder, and see the first characters of your password.
Or he might read HN, and see that your preferred passphrase method is composed of english sentences with common substitutions.
Maybe a website you're using leaks its password DB, and your "padding method" is exposed, reducing the search space back to what it was before the padding. I'm going to have to disagree with GRC here. "D0g.........." is a very bad password, especially if you use ".........." as your padding on every website.
Even without this, common substitutions like '3' for 'e' or '!' or 'i' are accounted for in everything but the most naive cracking tools.
Perhaps less likely, a timing attack in the auth system exposes the first few characters of your password, but not the rest.
Why put up with these issues, when something like xkcd's 4 random words works well, is easy to remember and type, and calculates entropy in a uncontroversial way?