Something that you can actually remember

  • comfy@lemmy.ml
    link
    fedilink
    English
    arrow-up
    21
    ·
    3 days ago

    Congratulations, everyone who didn’t say “password manager” just cut down the search space to crack their hexbear.net account password by a huge amount.

    • SootySootySoot [any]@hexbear.net
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      2 days ago

      This is a nonsensical criticism. A password of six random words has 2^77 possibilities. This means, even if they knew you were using this method, then with state of the art computing, we’re talking like the age of the universe to crack one. If they didn’t know, then we’re talking like 10^70 times that. A password of just a few words would be more than secure enough.

      Search space for cracking passwords, if Hexbear.net is doing any sort of half-decent hashing method, isn’t a very big deal beyond having more than like, 8 characters. If anything, having a common attack vector like a password manager could mean you’re even more likely to be done in.

      In a previous life I did a lot of MD5 password cracking, the problem has since been all but solved.

      • comfy@lemmy.ml
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        I admit it was a snarky joke from me, and more trying to be provocative about building a security culture than a proper criticism. You’re correct.

        (Neat to hear you’ve done some hash cracking in the past!)