logoalt Hacker News

GoblinSlayeryesterday at 5:34 PM2 repliesview on HN

Depending on the protocol they can be url encoded or even helpfully html encoded; the same password can be used over different protocols. It's the best to not use punctuation by default (length supplies more entropy than charset), I add -0 at the end to make dumb password policies happy.


Replies

abustamamtoday at 3:28 AM

Sorry I'm a bit lost here. Are you saying requiring a special character and a number are dumb password policies? Wouldn't charset AND length make for exponentially higher entropy? 52 (or 62 for digits) to the length power vs (62+20 special chars) to the length power? Or am I missing something?

show 1 reply
InitialLastNameyesterday at 8:53 PM

Often, the same ones with limited punctuation also have length limits, so maximizing the character options is the only way to maximize entropy.