Hacker News new | past | comments | ask | show | jobs | submit login

How are you making such a specific assessment without any knowledge of what the characters are?



It doesn't matter what the characters are; only what characters are potentially valid.


Would you say the password "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" has high entropy?

People have gotten their Bitcoin wallets owned with 60-character passphrases, because they used phrases that appeared in a Web crawl. Number of characters is not the important thing.


It would be reasonable to assume that someone who reads HN will understand that "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa" would not be good, even if it is 30 characters long. Donatj probably considered this.

That said, your point is valid and it's possible you're right.


That's obvious. What's not obvious is whether donatj's 30 characters are individually random or composed of words. And 'individually random' could mean anything between the 4 bits of hex and the >7.7 bits of codepage 1252.


What matters is what frequency distribution the characters were drawn from.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: