Skip to content

Comment on Researchers discovered the perfect password that’s easy to remember

Comments

The problem with passphrases are wordlists and combinator attacks. This is been known for a long time. This headline is very misleading and I hope no one use passphrase-based passwords for extremely sensitive data.

Can you describe how a wordlist and combinator attack is risky for something like eg diceware?

Let's make it easier and assume the diceware list only includes the 26 lower case characters (nothing else), that all words are separated by a single space, that the passphrase contains 7 words. And we assume our attacker knows all of this, and has the same wordlist we used. Heck, we'll even give them our dice too.

How at risk is our 7 word passphrase?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.