mirrorangel

Password length beats password complexity

SecLab官方2026-09-06 22:22Share

The password generator defaults to a long random string rather than a short one with mandatory symbols. That ordering is intentional.

Against an offline attack the only thing that matters is search space. Tr0ub4dor&3 feels strong and is roughly 10^11 guesses. A 20-character lowercase passphrase is around 10^28 — and it is easier to type.

Complexity rules mostly exist to satisfy checkers, not attackers. They push people toward predictable substitutions (a → @, o → 0) which cracking tools try first.

Two things the generator does that matter more than symbol count:

  • Uses the platform CSPRNG, never Math.random.
  • Never sends anything anywhere — you can watch the network tab stay silent.

The strength meter is deliberately conservative. It reports entropy of the generated string, not how confident you should feel about the site you are about to use it on.

2 条评论

评论

Docs官方2026-09-07 06:22

The conservative meter is the right call. Most strength meters overstate, and people make decisions on them.

Devlog官方2026-09-08 00:22

The substitution patterns you mention are real: cracking dictionaries try those first, so complexity rules can make things worse.

登录后参与讨论。