logoalt Hacker News

applfanboysbgonyesterday at 8:49 PM1 replyview on HN

SHA-256. Did you? My point isn't constrained to this exact service, though. My point is that the XKCD-style passphrase is in general not secure. If you make a habit of using it, assuming that the service in question will take care of securing it super duper safely on your behalf, you will get bitten when a service doesn't do this.


Replies

XorNotyesterday at 9:39 PM

If character class constraints are enforced then that password becomes incredibly strong though - e.g. require a capital, and special characters and a number.

Plenty of sentence passwords meet that but now the probability space has exploded.