Hacker News new | ask | show | jobs
by uptown 4668 days ago
If you're cautious enough to use a 26 character passphrase, why are you comfortable revealing how many characters your passphrase contains?
2 comments

Because even if it's just digits and numbers, 62^26 - 62^25 is a non-brute forceable keyspace.
ah, but it is a passphrase, not a password. Limiting phrases to exactly 26 chars doesn't seem that big anymore.
Good luck brute forcing an iPhone without it locking up forever though - regardless of your semantic considerations here.
It would be kind of ingenious to publicly reveal a false character count.

(A little paranoid, though.)