Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, it's equivalent to reducing k to 24 for a specific character, not reducing it to 1. For k=65 it reduces the search space by about 64%, or 1.43 bits entropy (ln (65/24)/ ln 2).

Though we know the first and last characters aren't special, so it's actually equivalent to reducing k to 18 for a single character, or 1.85 bits entropy lost by this rule and its interactions with the other rules.

... then the rule that the first and last characters can't be special reduces k from 65 to 62 for them, and the rule that no sets are allowed reduces k by 1 for every character after the first, and so on.

But really, I think the bigger concern is that all of these rules mean the password will end up on a post-it note stuck to the monitor.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: