this post was submitted on 15 Sep 2024
476 points (99.4% liked)

196

18076 readers
636 users here now

Be sure to follow the rule before you head out.


Rule: You must post before you leave.



Other rules

Behavior rules:

Posting rules:

NSFW: NSFW content is permitted but it must be tagged and have content warnings. Anything that doesn't adhere to this will be removed. Content warnings should be added like: [penis], [explicit description of sex]. Non-sexualized breasts of any gender are not considered inappropriate and therefore do not need to be blurred/tagged.

If you have any questions, feel free to contact us on our matrix channel or email.

Other 196's:

founded 2 years ago
MODERATORS
 
you are viewing a single comment's thread
view the rest of the comments
[–] SaltyIceteaMaker@lemmy.ml 1 points 10 months ago (1 children)

It's still less combinations than just scramble tho. It may be enough idk, but an algorithm that just combines words would definitely at some point arrive at like "SaltyIceteaMakerBlueAcorn" it's only once you add random letters/numbers/special characters that a dictionary attack stops working.

Although this probably doesn't matter as it would likely still take like a century or ten to complete

[–] Viking_Hippie@lemmy.world 0 points 10 months ago (1 children)

It's still less combinations than just scramble tho

Not in any meaningful way, no. There's what, hundreds of thousands of words in the English language? With no apparent pattern, that's a near-infinite number of possible combinations of 5 or 6 word phrases.

Add that most password crackers would use another kind of attack that presupposes that there's numbers and special characters and you really have redundancy on redundancy.

an algorithm that just combines words would definitely at some point arrive at like "SaltyIceteaMakerBlueAcorn"

Not within your lifespan or even that of humanity.

it's only once you add random letters/numbers/special characters that a dictionary attack stops working.

That's just not true if you don't consider "might theoretically get there in a million years" as "working".

Although this probably doesn't matter as it would likely still take like a century or ten to complete

Exactly. So your entire point is moot. A password or passphrase doesn't need to hold for longer than the existence of the account (or whatever's being protected by it), the user, or the species of the user.

[–] SaltyIceteaMaker@lemmy.ml 2 points 10 months ago (1 children)

Chill bro it was just me rambling about and even arguing against myself. Didn't have to make a whole callout post lol

[–] Viking_Hippie@lemmy.world 2 points 10 months ago (1 children)

I was just answering your arguments and didn't want to let all of that mental work go to waste when I saw the reveal at the very bottom 😄