Entropy isn't sufficient to measure password strength
1–10 of 124 posts
Re: Entropy isn't sufficient to measure password strength
#2Simple analogy - if the goal was to protect your house from a 9-foot-deep flood, would a dike with an average height of 10 feet do the job?
Re: Entropy isn't sufficient to measure password strength
#3Re: Entropy isn't sufficient to measure password strength
#4Re: Entropy isn't sufficient to measure password strength
#5Re: Entropy isn't sufficient to measure password strength
#6Maybe I just don't have trendy-enough coworkers or friends...but I know of no one who actually analyzes password strength in terms of Shannon entropy. Cripes, the very first sentence of the Wikipedia page for Shannon entropy tells us that it's an average . Simple analogy - if the goal was to protect your house from a 9-foot-deep flood, would a dike with an average height of 10 feet do the job?
Re: Entropy isn't sufficient to measure password strength
#7Maybe I just don't have trendy-enough coworkers or friends...but I know of no one who actually analyzes password strength in terms of Shannon entropy. Cripes, the very first sentence of the Wikipedia page for Shannon entropy tells us that it's an average . Simple analogy - if the goal was to protect your house from a 9-foot-deep flood, would a dike with an average height of 10 feet do the job?
Re: Entropy isn't sufficient to measure password strength
#8This is an argument I can't find anyone making: an aggregate average entropy of the set of all passwords you use is fine for password security, rather than the entropy of each individual password.
As far as I can tell this seems to be a (possibly intentional?) misunderstanding on the author's part.
Re: Entropy isn't sufficient to measure password strength
#9Re: Entropy isn't sufficient to measure password strength
#10The real question here is if there are any actually used password strategies where this distinction matters? In practice, no one would ever use the type of password strategy described.