• @ammonium
    link
    English
    101 year ago

    Four words is too low these days to protect against gpu bruteforcing

    • El Barto
      link
      English
      5
      edit-2
      1 year ago

      Got a source on that?

      Edit: plus brute forcing is just one scenario. I think the xkcd comic refers to using passwords in online services, and those usually have some sort of rate limiting.

        • El Barto
          link
          English
          31 year ago

          Sure, but the average English speaker knows way more than 2048 words. Let’s not forget about case sensitivity, made-up or “inside joke” words, names, and specific industry vocabulary.

          • @ammonium
            link
            English
            61 year ago

            Even if you take four words of a 30000 word list (quick Google says that’s the number of words an average person knows), that’s still less bits of entropy than a 5 word diceware password (7776 word list). People are also really bad at randomness, so your own string of random words is likely going to be much worse.