Wednesday, March 21, 2012

passphrases: how secure are they?

inspired by this tweet by @virusbtn suggesting that passphrases are very secure in theory. i question some of the basic assumptions of that theory when the best case scenario requires a 43+ character passphrase in order to rival a 10 character password (based on an entropy of 1.5 bits per character in english text versus an entropy of 6.555 bits per character of printable ascii).