3 ms·
Passwords are bound to be weak, you are right. Running PBKDF2 only gives some protection against password-cracking, but a well-funded adversary can overcome th
by maxtaco 13y ago
Passwords are bound to be weak, you are right. Running PBKDF2 only gives some protection against password-cracking, but a well-funded adversary can overcome that protection if the original password doesn't have enough entropy.
For passwords, I recommend using a sequence of 4-5 random words chosen from a ~20k word dictionary. This gives you about 58 to 72 bits of entropy.
I also recommend https://oneshallpass.com https://oneshallpass.com for giving random PWs to different Web sites, but that's a slightly different problem.