10000^4 = 10^16 ≈ 2^53.15
So only 53 bits of security. I wouldn't protect something like bitcoins with that. 10000^4 = 10^16 ≈ 2^53.15
So only 53 bits of security. I wouldn't protect something like bitcoins with that.So yeah, a randomly selected passphrase chosen from a pool for 10,000 words would work just fine. Assuming we're talking about secure software. For websites, use a password manager and then pick your poison for how you pick the master passphrase.
In reality you'd be lucky if all of it does one iteration. In which case it will only take a day on one machine.
You're also underestimating how massively parallel GPUs are becoming.
The more important question is - why settle for 53 bits and worry about it?
Trust nothing. KeePass let's you choose the number of iterations, and can autocalibrate. I believe it calibrated mine to >1mil iterations. I use KeePass to generate the passwords for pretty much everything else, except TrueCrypt (which uses ~1,000 iterations, but it's far more complicated than that). So the number of iterations everything else does is unimportant.
> You're also underestimating how massively parallel GPUs are becoming.
I'm a Bitcoin miner and developer. I know exactly how parallel GPUs, FPGAs, and theoretical cracking ASICs are. Only ASICs would be able to achieve 1 TH/s of cost effective cracking power, which is where I spec'd my estimate. Suffice it to say, that number I quoted is an underestimate; it would take a real attacker much, much longer. Unless we're talking about organized crime or the government here, in which case you can look forward to them spending a year of their entire computational power on just little ole you.
> The more important question is - why settle for 53 bits and worry about it?
That is why I asked what your criteria is. A line must be drawn somewhere. Humans aren't good at generating and/or memorizing passphrases. So picking a reasonable threshold is important. If 30 years of security against an unreasonably powerful attacker is not enough, what is?
Here's my comment in this same thread:
https://news.ycombinator.com/item?id=6864466
I agree that if you pre-hash your passwords 1 million times yourself, then it's much safer than using the password directly. You're basically slowing down the bruteforce attack by a factor of a million, which is equivalent to adding log2(1M) = 20 more bits.
53 bits is definitely not enough to protect anything important. I, personally, use 30 character passwords for anything mildly important, like email, which is around 170 bits. For bitcoins I go 40 characters - that's around 230 bits.
Per the table on page 107, 40-character user selected passwords have between 56-62 bits of entropy.
That's (ballpark) equivalent to 8 completely random characters, which is relatively hard to remember. I know, personally, I'd rather remember 1 word than 2 randomly chosen characters from a pool of ~100.
Easy to remember and easy to type.
What benefit does this have versus adding an additional word?
All my passwords are randomly generated, I set the minimum at 30 characters. My most important passwords are 40 to 50 characters.
I highly recommend a similar system. I feel a lot safer than when I had to remember passwords for my email accounts, banks, credit cards, Ebay, Paypal, my webservers, FTP, SSH.
I even store my credit card info in KeePass, so I don't have to type the 16 digits every time.
So if a single password is compromised, all of your randomly generated passwords are compromised? So what kind of password do you use for the keyring that you believe is better than memorizing a chain of words?
For reference, my longest pass phrase is a story constructed around ~30 random words, which using equivalency above, is about ~60 random characters. I don't have to rely on a password manager to keep it safe via a (probably weaker) password.
Anything beyond that is simply done via carrying a physical device with a key on it.
If you're using the printable ascii characters with fully random selection, that's 6.55 bits of entropy per character, for a total of 196.5 bits of entropy over 30 characters. For anything over 20 characters (=131 bits of entropy if randomly selected), you're implying that there is someone out there who can bruteforce the keyspace of AES (128 bits in the most common case), but can't install a keylogger on your system.
I also try to futureproof with using extra long passwords. Most of the time I copy-paste them anyway, so it doesn't matter.
The attacker wouldn't know which characters I used, so they will have to have a wider coverage anyway.
Keylogger is my worst fear, of course. But I try to be safe about the shit I download and how I browse the websites. I scan my PC for viruses, keyloggers and rootkits daily.