Hacker News new | ask | show | jobs
by jamesaguilar 5179 days ago
When the space of passwords denied by a rule is much, much smaller than the minimal search space, it doesn't matter all that much.
1 comments

Right. I think people make the mistake of thinking that, if you have 40 bits of entropy and then you delete some 20-bit entropy passwords, you only have 20 bits left. That's not how it works.

40 bits of entropy means 2^40; 20 bits means 2^20. 2^40 - 2^20 gives you something very, very close to 2^40 (39.9999986 bits of entropy.)