BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] vnc
- Subject: [Discuss] vnc
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- Date: Fri, 29 Aug 2014 15:14:55 +0000
- In-reply-to: <eb3be72d3c504bf7bc8b15bdc3e3162c@CO2PR04MB684.namprd04.prod.outlook.com>
- References: <53F9F6B9.4060505@stephenadler.com> <20140824161132.GE14848@randomstring.org> <be314521ab6bebb6add54d706b042f01.squirrel@mail.mohawksoft.com> <53FA1C3B.70908@gmail.com> <cb98ac9a77c99dd9313c5b1503d30ee1.squirrel@mail.mohawksoft.com> <e0e087b00e6b48f5ac53d81f1df7b74e@CO2PR04MB684.namprd04.prod.outlook.com> <20140828165736.GP14848@randomstring.org> <79840c0c0ee34d6f99ecb6f770505170@CO2PR04MB684.namprd04.prod.outlook.com> <20140828172210.GQ14848@randomstring.org> <eb3be72d3c504bf7bc8b15bdc3e3162c@CO2PR04MB684.namprd04.prod.outlook.com>
I know this is beating a dead horse, and also OT for the vnc topic. Suppose you pick a word randomly from a word list, suppose it's the GSL, and the word selection is worth approx 11 bits of entropy. If that word happens to be "a" then you have 11 bits per character. If the word happens to be "experience" then you have 1 bit per character. If you're choosing a sentence as a password, I think you should probably estimate its entropy using its word count rather than its character count. And since words are not selected randomly, you should not count 11 bits per word. To put a bound on that estimate - I claim 11 random words from the GSL gets you ~121 bits of entropy. On average this would be 64 characters plus separator character, so 74 characters total. By comparison, as Dan says estimate 1.1 bits per character in a sentence, that would be 110 characters. The ratio here is 0.67. This would mean that each word in a sentence is 0.67 times as random as a perfectly random word. I don't buy it. I swear that measurement is grossly overestimated. So if you introduce a fudge factor - let's just suppose that each word in a sentence is at most 0.2 times as random as a purely random word (seems about right by my gut feel). Then you'll need 5x more words in your sentence, which means 55 words. On average that will be around 320 characters.
- References:
- [Discuss] vnc
- From: adler at stephenadler.com (Stephen Adler)
- [Discuss] vnc
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] vnc
- From: markw at mohawksoft.com (markw at mohawksoft.com)
- [Discuss] vnc
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] vnc
- From: markw at mohawksoft.com (markw at mohawksoft.com)
- [Discuss] vnc
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] vnc
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] vnc
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] vnc
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] vnc
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] vnc
- Prev by Date: [Discuss] Why the dislike of X.509?
- Next by Date: [Discuss] vnc => passphrase entropy
- Previous by thread: [Discuss] vnc
- Next by thread: [Discuss] vnc
- Index(es):