2 ms·
The problem with your argument is that you are equating entropy with password strength. While entropy is a valid measurement of password randomness, it is not a
by m8urn 14y ago
The problem with your argument is that you are equating entropy with password strength. While entropy is a valid measurement of password randomness, it is not a direct measurement of how strong a password is. Take the password "vvvvvv.vvvvvvvvvv7vvvvvv" which has terrible entropy yet is very unlikely to be cracked. Why? because a cracker does not know that your password contains only three distinct characters and would still perform a brute force attack based on an assumption of higher entropy.
If you are talking about short passwords, entropy is critical in determining the strength of the password, but the true measure of a password's strength is the permutations required to perform a brute force attack. While range of character sets determine permutations, so does the password length. You can make up for one with the other, which is why "vvvvvv.vvvvvvvvvv7vvvvvv" is a very secure password.
That aside, I did address more of the math of the XKCD comic here: http://xato.net/passwords/analyzing-the-xkcd-comic/ http://xato.net/passwords/analyzing-the-xkcd-comic/