2 ms·
Yes, it is critical constraint - if you find it easy to remember. What's the size of random password space there?
by miga 12y ago
Yes, it is critical constraint - if you find it easy to remember.
What's the size of random password space there?
- csirac2 12y agoYou just prompted me to read the source code :-) gpw.c has this comment at the top: /* GPW - Generate pronounceable passwords This program uses statistics on the frequency of three-letter sequences in your dictionary to generate passwords. The statistics are in trigram.h, generated there by the program loadtris. Use different dictionaries and you'll get different statistics. This program can generate every word in the dictionary, and a lot of non-words. It won't generate a bunch of other non-words, call them the unpronounceable ones, containing letter combinations found nowhere in the dictionary. My rough estimate is that if there are 10^6 words, then there are about 10^9 pronounceables, out of a total population of 10^11 8-character strings. I base this on running the program a lot and looking for real words in its output.. they are very rare, on the order of one in a thousand. ... I'm not really in a position to properly figure this out... for a start, it's commonly claimed that there are 1M words used in English however my local /usr/share/dict/words has only 100K entries (and a even lot of those seem redundant). Assuming my gpw binary was "trained" on a 1M wordlist, and that my algorithm averages three 8-char strings per passphrase... and we take the comments at face-value, i.e. 10^9 possibilities per 8-char string generated. I'm going to pretend I can competently use Mlog2(N) to estimate that three such strings might make up 3log2(10^9)=89 bits of entropy. Throw in a 0-9999 number, let's pretend that's worth 13-ish bits, let's call it 100 bits? I haven't factored in the capitalizations yet, and I'm not sure how much the random placement of the numbers and the random lengths of each "word" are worth. IANACG (I am not a crypto guy) but that seems like a huge number of bits and so this is likely completely wrong (I'd start with going back to trying to properly analyze how many combinations my gpw binary can actually produces in an n-char string - that 10^9 combinations from a 10^6 wordlist needs testing).