Hacker News new | ask | show | jobs
by nakkijono 2017 days ago
Yeah, complexity sets are a bad method to estimate password entropy. Wheeler et al. [1] published pretty sound methods for estimating password entropy at the lower end of the entropy scale.

https://www.usenix.org/conference/usenixsecurity16/technical...