▲ 88 ▼ Massive data dump containing millions of passwords sparks security alert: Is your data safe? (www.techspot.com) submitted 2 years ago by throws_lemy@lemmy.nz to c/technology@beehaw.org 39 comments fedilink hide all child comments
[–] falsemirror@beehaw.org 12 points 2 years ago (3 children) Many PW managers let you generate passphrases, which are all around better than random strings. Length is the most important factor so finance-caffeine-utopia-redress-unseen Is way stronger and easier to remember (and type) than Fl7$j4FWw)&5O permalink fedilink source parent hideshow 6 child comments replies: [–] Myaa@beehaw.org 3 points 2 years ago Huh, TIL. I had no idea that was an option but that's super useful for things I need to type in on a device with no keyboard, or even things I can't access my password manager for. Thanks for the protip there! permalink fedilink source parent [–] Murkhat@feddit.de 2 points 2 years ago (2 children) Is it really safer? I mean when trying to bruteforce a password, one would have to make a guess whether it's a passphrase or not. But if you decided to check for pass phrases, wouldn't the one you posted be cracked in 5 times the amount of words in that dictionary? I'm not sure how large the vocabularies of the generators are, but I would guess a random 17 char password might be safer than a 5 phrases password? permalink fedilink source parent hideshow 4 child comments replies: [–] Scary_le_Poo@beehaw.org 5 points 2 years ago (1 child) but I would guess a random 17 char password might be safer than a 5 phrases password And you would be very wrong about that. A 5 phrase password has entropy. "finance-caffeine-utopia-redress-unseen" is 28 characters. If you add in a different symbol between the words and add a number somewhere, this password becomes incredibly difficult to brute force. I'll let xkcd explain it better. permalink fedilink source parent hideshow 2 child comments replies: [–] Murkhat@feddit.de 1 point 2 years ago Youre right,different separators, numbers and even capital letters change my theory alot permalink fedilink source parent [–] Areldyb@beehaw.org 1 point 2 years ago It'd be dictionary length to the fifth power, not times five. permalink fedilink source parent [–] esaru@beehaw.org 2 points 2 years ago* And pass phrases are faster to type and with less typos even though they need more characters than passwords to be the same secure. permalink fedilink source parent
[–] Myaa@beehaw.org 3 points 2 years ago Huh, TIL. I had no idea that was an option but that's super useful for things I need to type in on a device with no keyboard, or even things I can't access my password manager for. Thanks for the protip there! permalink fedilink source parent
[–] Murkhat@feddit.de 2 points 2 years ago (2 children) Is it really safer? I mean when trying to bruteforce a password, one would have to make a guess whether it's a passphrase or not. But if you decided to check for pass phrases, wouldn't the one you posted be cracked in 5 times the amount of words in that dictionary? I'm not sure how large the vocabularies of the generators are, but I would guess a random 17 char password might be safer than a 5 phrases password? permalink fedilink source parent hideshow 4 child comments replies: [–] Scary_le_Poo@beehaw.org 5 points 2 years ago (1 child) but I would guess a random 17 char password might be safer than a 5 phrases password And you would be very wrong about that. A 5 phrase password has entropy. "finance-caffeine-utopia-redress-unseen" is 28 characters. If you add in a different symbol between the words and add a number somewhere, this password becomes incredibly difficult to brute force. I'll let xkcd explain it better. permalink fedilink source parent hideshow 2 child comments replies: [–] Murkhat@feddit.de 1 point 2 years ago Youre right,different separators, numbers and even capital letters change my theory alot permalink fedilink source parent [–] Areldyb@beehaw.org 1 point 2 years ago It'd be dictionary length to the fifth power, not times five. permalink fedilink source parent
[–] Scary_le_Poo@beehaw.org 5 points 2 years ago (1 child) but I would guess a random 17 char password might be safer than a 5 phrases password And you would be very wrong about that. A 5 phrase password has entropy. "finance-caffeine-utopia-redress-unseen" is 28 characters. If you add in a different symbol between the words and add a number somewhere, this password becomes incredibly difficult to brute force. I'll let xkcd explain it better. permalink fedilink source parent hideshow 2 child comments replies: [–] Murkhat@feddit.de 1 point 2 years ago Youre right,different separators, numbers and even capital letters change my theory alot permalink fedilink source parent
[–] Murkhat@feddit.de 1 point 2 years ago Youre right,different separators, numbers and even capital letters change my theory alot permalink fedilink source parent
[–] Areldyb@beehaw.org 1 point 2 years ago It'd be dictionary length to the fifth power, not times five. permalink fedilink source parent
[–] esaru@beehaw.org 2 points 2 years ago* And pass phrases are faster to type and with less typos even though they need more characters than passwords to be the same secure. permalink fedilink source parent