Hacker News new | ask | show | jobs
by canjobear 1620 days ago
Cool example. An attacker will take 2^234 guesses on average to guess the password, but that's an average of 19 1's and one enormous number. So the attacker will usually guess the answer quickly. It's kind of like the St. Petersburg paradox in that the expectation value doesn't reflect typical behavior.

Seems like this might be a use case for "dispersion" (the second moment of entropy) [1].

[1] https://math.stackexchange.com/questions/1626522/higher-mome...