Hacker News new | past | comments | ask | show | jobs | submit login

I'm curious to know where the 80 bit number comes from? The 61 bits seems like a crazy large number to try and brute-force, but perhaps there are other issues besides brute force that I'm not considering?

Unfortunately while changing the 10 to 13 was a rather trivial change yesterday, now that the site has launched its not really possible. It would change and break everyones password on the site.

That said the entire thing is open-source, so anyone 'could' set up a version of password.ly with length=13 for themselves if they wanted.




Probably from NIST Special Publication 800-63. Level 3 authentication requires cryptographic keys with an entropy of at least 80 bits. http://csrc.nist.gov/publications/nistpubs/800-63/SP800-63V1...


You should consider making the password generator versioned, there may be many breaking changes between now and the day it dies.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: