Friday, July 10, 2009

[udfnzmgx] Password complexity practical limit

You can make your password or passphrase longer and or more complex. You would think that the longer it is, the more secure it would be, but after a certain point, about 70 bits of real entropy, no practical amount of brute force attack can possibly discover it. After this point it's no longer useful to make your password longer or more complicated. An adversary seeking to discover your password will employ a keystroke logger (keylogger) which will be equally effective no matter how long your password is.

No comments :