Hacker News new | ask | show | jobs
by kevhito 3495 days ago
Everything in the article is spot on, I only wish they went further and recommended passphrases more strongly. It's correct horse battery staple and all that.

As for your calculation, you are about right. Except memorizing a completely random 8 character password drawn from an 80 symbol alphabet is /extremely/ unpleasant for most people, especially when you may have a few different passwords you use on a daily or weekly basis. And for passphrases, 6 words drawn from a 4096-word dictionary is typical. I use that setting (or even 8 words for more important things) and have easily memorized about a dozen passwords, even ones I use only once every few weeks.

40966 = 4.7e21, about the same as an 11-character random password.

1 comments

So you have memorized the equivalent of a 60-word nonsensical poem?
Well, you only need to memorize the passphrase of your password manager's file.