3 ms·
If it's on a password list.
by codeflo 13y ago
If it's on a password list.
- bigiain 13y agoOr its less than 8chars against an attacker with a single laptop, or 10 chars against an attacker with a modern GPU, or 12 chars against a criminal gang with access to a few hundred GPUs, and I suspect you want at least 15 or 16 chars to feel reasonably future-proof against a nation-state level attacker, and I'm guessing 20chars is enough to ensure the NSA gets out the $5 wrench instead of powering up the supercluster to crack your password. Hashcat is _fast_. It's unlikely the NSA is many of orders of magnitude faster though. I'm happy enough with my 25 random char passwords generated and stored in 1Password.