2 ms·
From a quick skim of the paper, it doesn't seem like they mention how they acquired the data, other than some mention of how it's secured by their rate/count-li
by shabble 11y ago
From a quick skim of the paper, it doesn't seem like they mention how they acquired the data, other than some mention of how it's secured by their rate/count-limiting process.
I'd hope they're storing it all as one-way digests, and it occurs to me that their strength metric (% number guessable given X attempts) might in fact be them brute-forcing their own data. Or they could log the inputs and result of each attempt by actual users during their experiment.
Or they could be secretly parsing and storing it all, and consequently know enough about you to guess most of your other services, should they NSL^Wneed to.
" For example, it was estimated that it actually takes over
2^100 guesses to compromise an average password due to the presence of less than one in a million users choosing 128-bit random strings as passwords"
I'll be the one looking smug until I misplace my personal password database.