Hacker News new | ask | show | jobs
by MattPalmer1086 1620 days ago
The argument feels like a straw man.

He seems to be saying, if your password selection strategy skews towards really weak passwords, and you measure the Shannon entropy of the distribution, it won't reveal that this is a bad strategy.

I don't know anyone who would actually do this and declare a win "because Shannon".

At best, it's mildy interesting that Shannon entropy on its own isn't going to give you a useful answer if you have a weak strategy.