Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Fundamentally is there any flaw with this method? Or a reason why it isn't better than general password approach?


You can only remember a limited number of passwords regardless of whether it's a sequence of words or a sequence of random characters. The main flaw in all these schemes is that you have to remember them. The only viable option is to use a password manager.


It's vulnerable to the dictionary-based attacks that are very common.


Diceware is designed to make passwords against dictionary attacks. Estimates of diceware entropy begin with the assumption that an attacker has the dictionary. A dictionary with 6^5 entries would take 6^5^N guesses to exhaust (assuming the entries are randomly chosen). 6^5^4 = 2^52.


That is a sadly too often repeated lie. If you know otherwise please explain/link how the attack works, how can you guess the 4 words? Effectively, that would mean requiring much less than 2^44 attempts as xkcd explains.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: