Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Even assuming just upper/lowercase and 20 characters you are looking at 114 bits of entropy.

Careful, that math assumes each character was chosen randomly, which isn't how people usually pick passwords. If the password contains words and patterns, then it was much weaker. "Passwordpasswordpass" matches those requirements, and is decidedly weak.

But I agree, password reuse or other similar mistake seems likely.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: