Replying to Avatar Cyph3rp9nk

These tables circulating on the internet of brute force password hacks are totally incorrect.

These tables only work for passwords generated randomly by computers or applications such as KeePassXC, if the password is generated by a human they are useless, since humans are predictable and when a password is hacked by brute force different types of dictionaries are used which substantially shortens the hacking time.

If you want to measure well the entropy of your password with an algorithm that takes into account dictionary attacks and predictive attacks use the KeepassXC calculator.

Recommendation: Never use human generated passwords.

Avatar
ynniv 1y ago

This chart is also misleading when it says "Password hash: bcrypt". Bcrypt is used with a work factor that should be set as high as practical for your server. Not listing the work factor means that the absolute numbers listed are meaningless.

Reply to this note

Please Login to reply.

Discussion

No replies yet.