• psud@aussie.zone
    link
    fedilink
    English
    arrow-up
    0
    ·
    21 hours ago

    My workplace has finally gone to passphrases and 1 year password life, which is nice as it’s a password I often need to type, so I’d rather 20 easy to type and memorise chars than 16 random

    • flatbield@beehaw.org
      link
      fedilink
      English
      arrow-up
      0
      ·
      edit-2
      12 hours ago

      The missleading thing about passphrases is that anything a human can remember is low entropy. That it has 20 charachers says nothing about how random.

      Edit: I also wonder how much randomness is really needed. Properly salted and hashed passwords shoud not need that much randomness. Lot of this is about users just choosing bad passwords, reusing, and IT not properly salting and hashingon their end.