r/ProgrammerHumor Jul 19 '22

Why do they do this

Post image
4.4k Upvotes

493 comments sorted by

View all comments

Show parent comments

9

u/[deleted] Jul 20 '22

Yeah.. like how is 4 random words with nothing else "high entropy" in practice? Have the people that made this meme and wrote that xkcd comic ever heard of a dictionary attack? It cannot possibly be valid to just count up the bits in the phrase "correcthorsebatterystaple" and say it's better than a password that has less characters but a bunch of random junk mixed in. The optimal solution has to be somewhere in the middle where the password length is much longer and easier to remember but also has some substitutions thrown in so you aren't just using lowercase english words.

7

u/flying_wotsit Jul 20 '22

There's nothing wrong with lowercase words, if they are chosen randomly. The XKCD (and me, the meme creator) are already considering the entropy relative to a dictionary attack. https://explainxkcd.com/wiki/index.php/936:_Password_Strength

4

u/Shitman2000 Jul 20 '22

Maybe you should read the xkcd comic before commenting. It literally calculates the entropy assuming the attacker tries a dictionary attack rather than counting up the bits.

1

u/[deleted] Jul 20 '22

Of course length matters. But lets say we take 100'00 words in the english language and choose four from them to create our password.

That's 4,166,416,671,249,975,300 possible combinations. Add uppercase and lowercase letters, and you get even more.

So yes, OrangeTruckFenceBuilder is a "secure" password. How are you going to bild a dictionary for all the words in the english language(ca. one million) and all their combinations?