Linked by Howard Fosdick on Sat 10th Nov 2012 07:28 UTC
Thread beginning with comment 542133
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
Since that's the strategy, it doesn't really make passphrases any less secure since they're just going to attack a whole lot of accounts and get as much as they can. There will always be people with weak passphrases.
But nearly all passphrases are weak and that's why they're less secure. I've stated this several times now. In fact, did you even read the fucking link I provided?
The whole passphrase point is taken directly from professional security experts who specialise in cracking passwords and thus hardening systems against such attacks. But as usual, you know better.
I swear to God, sometimes chatting on here is like pulling teeth <_<
There's nothing stopping crackers from targeting password hash generators either.
You can't target hash generators for my method. the hash generator is only used as a method to create a random password. You could just as easily mash the keyboard for all the difference it makes. Except with my method you don't need to store the password anywhere.
You haven't the slightest idea what you're talking about, so I beg you, please, for the love of God, read the link I provided. Do yourself a favour and educate yourself on this subject because at the moment it's pretty clear that your understanding is outdated at best.
"There's nothing stopping crackers from targeting password hash generators either.
You can't target hash generators for my method. the hash generator is only used as a method to create a random password. You could just as easily mash the keyboard for all the difference it makes. Except with my method you don't need to store the password anywhere. "
Why can't you target hash generators? After all, to generate your hash, you're basically using a passphrase and the website for the salt.
If passphrase cracking is as easy as you say it is, then it's just as easy for a cracker to figure out the passphrase you use to generate the hash.
Edited 2012-11-12 13:27 UTC





Member since:
2007-02-18
Since that's the strategy, it doesn't really make passphrases any less secure since they're just going to attack a whole lot of accounts and get as much as they can. There will always be people with weak passphrases.
There's nothing stopping crackers from targeting password hash generators either.