Hacker News new | ask | show | jobs
by Splines 5179 days ago
I think it's interesting that "correcthorsebatterystapl" is more secure than "correcthorsebatterystaple".

Makes sense, but it's amusing to see the time drop as you add letters.

1 comments

I noticed this too. It seems advice to "pick random words" should be extended to "pick random words and leave the last letter off".
That only doubles the size of the attacker's dictionary, though. Instead, I'd say "pick random words and add a few random typos". As long as there aren't too many the typos will be as memorable as the words themselves (more so if you're a spelling pedant like me), and using a variety of typos instead of just one simple transformation increases the search space a lot more.