BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Password managers
- Subject: [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- Date: Wed, 6 May 2020 19:32:49 -0400
- In-reply-to: <5eb2fac0.1c69fb81.34622.b7dd@mx.google.com>
- References: <9c4a5c7e-55aa-8ae1-da3b-4512cb2ae85c@gmail.com> <5eb1f81d.1c69fb81.80c8b.07ca@mx.google.com> <CANiupv686GBC5EZVsiEf831-b4i0E3NjZ3fnsDToM02z1zjUNg@mail.gmail.com> <5eb223cd.1c69fb81.6fa04.3ab5@mx.google.com> <0cbc8403-48a5-14bd-524c-a4eded6b64fa@borg.org> <e2be00f8-8de6-4645-e71b-a5d14f78ede7@borg.org> <5eb2d4b7.1c69fb81.c9540.9f0b@mx.google.com> <2fc76d5b-e5bd-2aa4-7002-7e7b65461d76@borg.org> <5eb2f4ba.1c69fb81.676b1.a824@mx.google.com> <bc8f39ad-543c-9be6-169b-b8b2c13261a9@borg.org> <5eb2fac0.1c69fb81.34622.b7dd@mx.google.com>
On 5/6/20 1:58 PM, Rich Pieri wrote: > You tell me why you think 16 random characters is inappropriate for > this purpose. The reason for making passwords long is to make them unguessable. The key feature of a password is that, though I can make up guesses as fast as I choose to spend the money, there is a limit to how fast I can check my trove of passwords. I can only check them as fast as some limited-capacity server lets me. And an evenly slightly competently written server has explicit rate limiting. And any server on the open internet is subject to lots of probing traffic...limiting it limits one's AWS (or electric) bill if nothing else. 16-random characters? Which? Let's assume just lower case ASCII alphabetics. ?26^16 is 43608742899428874059776L That is a big number. (Add uppercase and numbers and other printable stuff...and 52**16 and 96**16 are both crazy bigger.) If your attacker started brute forcing that lowercase password at the start of the universe, and had been checking 100K guesses per second ever since, your attacker would be finishing up any millennium now. What is the point? Conversely, what is the cost? The cost is passwords that are completely unusable for mere human beings. Unusable is bad security. -kb
- Follow-Ups:
- [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- References:
- [Discuss] Password managers
- From: j.natowitz at gmail.com (Jerry Natowitz)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: sweetser at alum.mit.edu (Doug)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- From: kentborg at borg.org (Kent Borg)
- [Discuss] Password managers
- From: richard.pieri at gmail.com (Rich Pieri)
- [Discuss] Password managers
- Prev by Date: [Discuss] Password managers
- Next by Date: [Discuss] Password managers
- Previous by thread: [Discuss] Password managers
- Next by thread: [Discuss] Password managers
- Index(es):