> But this blurb fails to mention that the user provided passcode can only be about 15 bits of user supplied entropy…
How do you figure that?
How do you figure that?
log(10000)/log(2) ~ 15.
[1] http://www.engadget.com/2014/03/05/how-to-set-up-a-complex-p...
Of course this isn't ever actually used - in practice users choose four to eight digit passcodes.
Users should, if they want to secure their information, use a randomly chosen passcode of approximately 30 digits long.