Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

On what basis is that "very easy"? Four words from 1600 is 1600^4 permutations, which would take over 200 years to test at a 1000/second attack.

Sure, if we're talking about a different type of password, and 2-billion-tries-per-second attacks, it'll fall in about an hour, but simply pushing that out to six words from that dictionary will still stymie that level of attack for a couple of hundred years. The size of the dictionary is much less important than the length of phrase you generate from it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: