This comic says that a password such as Tr0ub4dor&3 is bad because it is easy for password cracking software and hard for humans to remember, leading to insecure practices like writing the password down on a post-it attached to the monitor. On the other hand, a password such as correcthorsebatterystaple is hard for computers to guess due to having more entropy but quite easy for humans to.

When I calculate entropy for the xkcd Password Strength (comic 936) I don't get nearly the amount of entropy stated in the comic. So why doesn't the the first password Tr0ub4dor&3 have an en.. xkcd Password Generator. The button below will generate a random phrase consisting of four common words. According to yesterday's xkcd strip, such phrases are hard to guess (even by brute force), but easy to remember, making them interesting password choices. correct horse battery staple. It's a novel idea, but xkcd stops short of actually recommending such passwords, and so will I. Use at.

  1. Looking at the XKCD comic, and at examples of real world passwords, we see that most users have passwords much much weaker than the XKCD example. A bunch of users will do exactly as the first panel says - they'll take a dictionary word, capitalize the first letter, do some gentle substituting, then add a number and symbol to the end
  2. The xkcd comic concludes that is it better to use a passphrase of 4 random words rather than a single-word password which has some known substitutions in it. It further presents some statistics about the entropy of the passwords. I wanted to prove this password strength and wanted to calculate the differences between a few password settings. (I say
  3. The famous xkcd comic about password strength calculates the entropy of the 11-character password Tr0ub4dor&3 with 28 bits of entropy.. When following the ASCII-95-chart, we have 95 possible letters, numbers and symbols for each character position. So in my understanding of entropy that password would rather be $95^{11} \,\widehat{\approx}\, 2^{73} \widehat=\, 73$ bits of entropy

The writer of the original article makes the point (which is what the xkcd comic points to) that passwords using three or more dictionary words, has more entropy and is thus harder to crack, therefore making them more secure. While there is a bit of truth to the article, it leads to some false understandings of how hackers actually go about hacking passwords, and make assumptions that aren't. The passwords generated by VeraCrypt are not the ones the comic is mocking. They're perfectly fine from an entropy standpoint, but problematic if you have to memorize them. It's a subtle but important distinction: the ones the comic is mocking are human-generated passwords made by manipulating words int This xkcd comic suggests what is essentially diceware over the traditional patterns. Diceware isn't a new concept, but it's definitely not as popular for creating passwords. The idea here is to create memorable secrets, chosen at random, with high levels on entropy compared to traditional passwords. I think this is definitely a better direction, and I like that people are thinking about this. This comic was directly referenced in the title text of 1286: Encryptic. Transcript [Black Hat is standing to the left behind Cueball, who is sitting in an office chair at his desk working on his computer. A message from the computer is indicated with a zigzag line from the screen.] Black Hat: Password entropy is rarely relevant. The real. On a side note, I started using the xkcd method since the comic came out. However, there is one thing he overlooked, which is that many websites have different restrictions on passwords (max length, no spaces, must use a capital and a punctuation and a number and a symbol, etc...). The result is that it's really tough to remember all the variations you put on your password : Continue this.

With your password if a password cracker knows the formula than it simply has to guess the initial word (11bits of entropy per word seems to be reasonable assumption). Now you might be tempted to mix it up. Change each direction from that example? Well you have 8 directions you could go so that's log2(8)=3bits of entropy per mixed up direction (not even including the reduced entropy as some. Talk:936: Password Strength. Explain xkcd: It's 'cause you're dumb. Jump to: navigation, search. Fix the software first. If you double the time it takes to enter each repeated password attempt you make brute force attacks pointless. Imagine you allowed a hurried user who screws up their own password entry w/ frozen fingers. If their system starts out with a 1 second delay, then doubles to two.

Passphrase vs. password entropy. Ask Question Asked 2 years, 3 months ago. The reason that XKCD comic is so cited isn't just the math - it's that people who haven't seen the comic in years can still tell you what that password is. That's the point of the comic: that those bytes of entropy were easy for a human to remember. Second, you might want to take a look at: https://wpengine.com. This video is unavailable. Watch Queue Queue. Watch Queue Queu use the following search parameters to narrow your results: subreddit:subreddit find submissions in subreddit author:username find submissions by username site:example.com find submissions from example.co Confused about (password) entropy. Ask Question Asked 7 years, 6 months ago. Active 2 years, 3 months ago. Viewed 25k times 39. 11. There seem to be many different 'kinds' of entropy. I've come across two different concepts: A) The XKCD example of correcthorsebatterystaple. It has 44 bits of entropy because four words randomly chosen from a list of 2048 words is 4 * log2(2048) = 44 bits of.

Yes, it is true. Really you should only count the parts of your passwords complexity that are generated by a completely random generator, because humans are fallible. Therefore I have no problem telling the world here that my gmail password is m..

