Author Topic: BL authentication keys make really really good passwords  (Read 6831 times)

using its the nutshack takes 224 million years to crack
we are number one is 10 billion
now look at this net is 919 trillion
tito richard richardman baby is 2 quintillion years
Nigerian cunts is 111 thousand
llanfairpwllgwyngyllgogerychw yrndrobwllllantysiliogogogoch uchaf.com is 461 novemvigintillion years
the password is password is 4 lovetillion years
jesus christ

thats why you make intentional typos
hackers are not dipstuffs and have programs that put in intentional typos because that is a known trick
they limit it to the most likely intentional typos like changing an e to a 3 or vice versa, but usually hackers know of these tricks and you need to think around them

usually a really good password is 10 characters or longer with randomly assembled uncommon words. numbers and special characters added in this good password would make it even better especially if you just add them in randomly
« Last Edit: November 15, 2016, 10:33:57 PM by Gytyyhgfffff »

usually a really good password is at least 32 random characters, including capital and lowercase letters, numbers, and symbols, used in combination with a password manager

yeah a password like that would be impossible to crack if hackers are cracking a forgetton passwords from a leaked database from a website which is usually what happens. they wouldn't have enough time to spend cracking your account when there's many others with much weaker passwords that could pay out better

lol from the looks of things we should just get rid of passwords altogether

hackers are not dipstuffs and have programs that put in intentional typos because that is a known trick
they limit it to the most likely intentional typos like changing an e to a 3 or vice versa, but usually hackers know of these tricks and you need to think around them

usually a really good password is 10 characters or longer with randomly assembled uncommon words. numbers and special characters added in this good password would make it even better especially if you just add them in randomly
no i meant hardcore intentional typos
eye instead of i
that sorta thing

i think the chances of someone taking the effort to crack your password is lower than whatever bot they use to crack it

lol from the looks of things we should just get rid of passwords altogether
this would be a cool idea to see, like fingerprint scanners or some stuff, but it'll be massively expensive and if you lock off passwords and replace them with scanners of some kind (or any other method of authentication) you're basically shutting off a lot of people from accessing their accounts because they won't be able to afford fingerprint scanners or retina scanners or richard scanners or whatever

no i meant hardcore intentional typos
eye instead of i
that sorta thing
that could work but remember hackers are cunning and in some cases make a living off of thinking of good ways to crack passwords. some of them would probably think of this. i suggest replacing characters like z with eye instead, that'll probably work better because that's an uncommon way of making your password complicated. making your password good is basically combining a bunch of uncommon elements together because password crackers rely on people using the same methods to make their passwords so they can crack them
« Last Edit: November 15, 2016, 10:45:57 PM by Gytyyhgfffff »

i think the chances of someone taking the effort to crack your password is lower than whatever bot they use to crack it
unless you are some kind of CEO or something, someone is unlikely to spend any time trying to figure out your password specifically (and frankly if you are targeting a single person there are far more effective and faster methods than brute forcing)
more likely, one of your passwords will at some point be involved in a hack of some website, and they will just be brute forcing it along with all of the others. then they'll have your password and your username, and depending on the site, possibly a few other websites where you happen to have an account. and of course they'd try the usual bank websites. if your passwords are all randomized, you're pretty much good to go. not only are all your other accounts uncompromised, but picking a new password to use on the victim site is trivial

unless you are some kind of CEO or something, someone is unlikely to spend any time trying to figure out your password specifically (and frankly if you are targeting a single person there are far more effective and faster methods than brute forcing)
yes basically the goal is to make your password complicated enough that whatever bot cracking it gives up because it has to move onto more vulnerable targets because there will be more vulnerable targets and cracking a bunch of accounts with weaker passwords is better for them compared to only cracking one account's difficult password. i personally don't believe in these fancy password creators but they would get the job done for this case

i personally don't believe in these fancy password creators but they would get the job done for this case
why? not only is it incredibly convenient for passwords, but 1password at least also lets you store other information, from driver's license info to credit cards to random notes that you just want to keep secret. also implements HOTP and TOTP for two-factor authentication
they get the job done for any case. if you hand type all your passwords, you will get annoyed having to type actually secure passwords, and decide to use insecure ones. a password manager fixes that, and makes it so much more convenient

imho they don't
since the first two characters are always AA, that's already 2 letters down

and if somebody got the hash and knew that password was a key, they could just guess the rest of the letters like aa(3 guesses)-(5 guesses)-(4 guesses)-(4 guesses)
so it'd be 16 characters to guess (which while it is secure it's still a bad idea to)
don't do it, you cigarettes
Nah, it always starts with A but after that it can be something like A-G or A-H.
And after that, blockland keys have 10 effective characters, each with 32 possibilities. That's a total of 68 bits of entropy that you have to brute force. That's not beyond the resources of someone with hundreds of thousands of dollars, but... The chances of someone wanting to spend that much money just to get your blockland key is negligible. If you want to be extra generous it would be 12 characters with 32 possibilities each, for 78 bits of entropy. That's getting into the many hundreds of thousands to low millions.
« Last Edit: November 15, 2016, 11:15:57 PM by Ipquarx »



The lyrics to Bohemian Rhapsody

Nah, it always starts with A but after that it can be something like A-G or A-H.
And after that, blockland keys have 10 effective characters, each with 32 possibilities. That's a total of 68 bits of entropy that you have to brute force. That's not beyond the resources of someone with hundreds of thousands of dollars, but... The chances of someone wanting to spend that much money just to get your blockland key is negligible. If you want to be extra generous it would be 12 characters with 32 possibilities each, for 78 bits of entropy. That's getting into the many hundreds of thousands to low millions.
huh, i thought it always started with aa

Get on my level. My passwords are 32-64 character random strings including upper and lower case, symbols, and numbers. They're kept in a .txt file so I'm forgeted if someone gets their hands on it.