Live data from Hacker News

The password “ji32k7au4a83” has been seen over a hundred times

twitter.com

291–296 of 296 posts

Re: The password “ji32k7au4a83” has been seen over a hundred times

#291

Earlier quoted context omitted.

I wasn't making that claim.

Then I have absolutely no idea what you were trying to claim in the second sentence of https://news.ycombinator.com/item?id=19304761 But we don't seem to be resolving anything so I'll just hope you have a good week.

You indirectly state that I claim "knowing the character pool of a password lets you reliably predict if n is sufficient."

Please point to the part of my statement which reflects this idea.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#292

Earlier quoted context omitted.

Then I have absolutely no idea what you were trying to claim in the second sentence of https://news.ycombinator.com/item?id=19304761 But we don't seem to be resolving anything so I'll just hope you have a good week.

You indirectly state that I claim "knowing the character pool of a password lets you reliably predict if n is sufficient." Please point to the part of my statement which reflects this idea.

"a function of the size of your character pool, because if your password is short enough for n-1 to contain a significant percentage of possible combinations then it's probably already short enough to brute force anyway"

This seems to say that a small character pool, aka "n-1 containing a significant percentage of possible combinations", implies that your password is "probably already short enough to brute force".

So small character pool means that "probably" the password is short/weak.

I'm saying that a small character pool does not imply that a password is "probably" short/weak.

And to be very clear: Using the size of the character pool to say it's "probably" weak is a form of "reliably predict[ing] if n is sufficient".

What am I misreading?

Re: The password “ji32k7au4a83” has been seen over a hundred times

#293
post #167

Earlier quoted context omitted.

While you're correct mathematically, I still think it's a good habit to give zero information about your password. If you attempt to estimate the information leakage with every "hint", sooner or later you'll slip up.

My view is your secrets should be secure even if the attacker knows everything about how they are generated and used. For example: My password is 8192 characters long, leveraging only the ASCII character set (except \n\r\t\0) It is changed every 28days at 11:05am It is only used on exactly 1 website and the username on that website is also only used on that website and randomly generated as well. Good luck (Tell me h…

This is a very hilarious post. Bravo, sir, or brava, madam. (Revealing your gender would likely be a security risk - if you leave that unspecified it doubles the space of possibilities!) I don't know what joyless types would downvote you.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#294

Earlier quoted context omitted.

You indirectly state that I claim "knowing the character pool of a password lets you reliably predict if n is sufficient." Please point to the part of my statement which reflects this idea.

"a function of the size of your character pool, because if your password is short enough for n-1 to contain a significant percentage of possible combinations then it's probably already short enough to brute force anyway" This seems to say that a small character pool, aka "n-1 containing a significant percentage of possible combinations", implies that your password is "probably already short enough to brute force". So…

> What am I misreading?

> So small character pool means that "probably" the password is short/weak.

I really don't know how you came to that conclusion. I never claimed any dependence between the character pool length and password length. They're obviously completely separate properties.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#295

Earlier quoted context omitted.

"a function of the size of your character pool, because if your password is short enough for n-1 to contain a significant percentage of possible combinations then it's probably already short enough to brute force anyway" This seems to say that a small character pool, aka "n-1 containing a significant percentage of possible combinations", implies that your password is "probably already short enough to brute force". So…

> What am I misreading? > So small character pool means that "probably" the password is short/weak. I really don't know how you came to that conclusion. I never claimed any dependence between the character pool length and password length. They're obviously completely separate properties.

You said that if a password of length n-1 "contains a significant percentage of combinations" compared to a password with length n then "it's probably already short enough to brute force".

Right?

That percentage comes entirely from the character pool.

So character pool -> percentage -> probably short enough to brute force.

What am I reading wrong? The only assumption I made is "compared to a password with length n", because what else would you be comparing length "n-1" to. Otherwise it's a direct quote.

Re: The password “ji32k7au4a83” has been seen over a hundred times

#296
post #236

Earlier quoted context omitted.

Firstly, that's irrelevant and doesn't make your actions acceptable. Secondly, indirect insults due to ignorance are more forgivable than a direct verbal attack.

I did not insult nor verbally attack anyone. I expressed my mood. I'm sure people here have a thick skin... or not.

Questioning the toughness of fellow commenters belies your effort to engage in good-faith intellectual discussion.
Post reply on HN