4 ms·
Yes, I agree that using a password manager that auto-generates random password is the way to go for protecting against the attack of a compromised hashed passwo
by jervisfm 13y ago
Yes, I agree that using a password manager that auto-generates random password is the way to go for protecting against the attack of a compromised hashed password database table.
Here is the thing I'm wondering though: in the case when brute force attacks is not practical, is using human generated password/passphrases really that bad when compared against randomly generated password? Most decent and important sites would throttle the number login attempts one can try before at least throwing up a captcha or outright blocking.
This implies, to me at least, that in such a scenario using something like 12 character human generated password would give about the same effective security as a longer randomly generated one (e.g. 24 character random password). Yes, the randomly generated password is objectively better from a theoretical standpoint but I am thinking the effective difference in reality is negligible in the case when a brute force attack is infeasible (due to throttling of attempts). Thoughts?
- jarrett 13y ago> Most decent and important sites would throttle the number login attempts one can try before at least throwing up a captcha or outright blocking. The types of attacks discussed in the article are not feasible when the only way to try a guess is to send an HTTP request. Look at how many guesses per second those GPUs are doing. You won't get anywhere near that sending HTTP requests. Passwords are far, far more likely to be cracked if the database of hashed passwords is compromised. That's what you should really be worried about, and it's the main reason to use strong passwords. Also be sure not to reuse passwords, even strong ones. A strong password can still be compromised, because there are many types of attacks that have nothing to do with cracking hashes.