Hacker News new | ask | show | jobs
by mekwall 4903 days ago
I think 80 is overkill. I'd say anything above 60 is secure enough for most passwords. One of my main password (consisting of only lowercase letters) has an entropy of 78.7 bits, which is good enough to safely guard sensitive information like financial records, but then again, it's 21 characters long :)
1 comments

It has less entropy now that you've given away some information about it.
Matters not. You still have no idea which one of my main passwords, how many they are nor where its used. Also, this particular password is non-critical which is why I used it as an example, but you're welcome to try and hack my accounts ;)
A 21-character password chosen randomly from [a-z] would have about 98 bits of entropy. But better be random.