628
you are viewing a single comment's thread
view the rest of the comments
[-] LostXOR@fedia.io 1 points 1 week ago

I'm not arguing that random passwords are better for everyone, just that they're most secure for their length. A 9 word passphrase is just as secure as a 16 character random password, but is far longer.

A 4 word xkcd passphrase is more or less equivalent to a 7 character random password, and is secure with xkcd's threat model (online brute force attack) but not with other threat models, like a brute force of a weak hash, which is many orders of magnitude faster.

If you'd like to verify the math:
4 word xkcd passphrase: 2048 (possible words) ^ 4 (number of words) = 44 bits of entropy โ‰ˆ 17.6 trillion possibilities.
7 word password: 70 (possible characters) ^ 7 (number of characters) โ‰ˆ 42.9 bits of entropy โ‰ˆ 8.2 trillion possibilities.
(Adding an eighth character raises the number to 576 trillion).

this post was submitted on 18 Jul 2025
628 points (100.0% liked)

memes

16512 readers
2366 users here now

Community rules

1. Be civilNo trolling, bigotry or other insulting / annoying behaviour

2. No politicsThis is non-politics community. For political memes please go to !politicalmemes@lemmy.world

3. No recent repostsCheck for reposts when posting a meme, you can only repost after 1 month

4. No botsNo bots without the express approval of the mods or the admins

5. No Spam/AdsNo advertisements or spam. This is an instance rule and the only way to live.

A collection of some classic Lemmy memes for your enjoyment

Sister communities

founded 2 years ago
MODERATORS