[ home / board list / faq / random / create / bans / search / manage / irc ] [ ]

/sci/ - Science and Mathematics

Spending thousands of dollars on useless labs since 2014.

Catalog

8chan Bitcoin address: 1NpQaXqmCBji6gfX8UgaQEmEstvVY7U32C
The next generation of Infinity is here (discussion) (contribute)
A message from @CodeMonkeyZ, 2ch lead developer: "How Hiroyuki Nishimura will sell 4chan data"
Name
Email
Subject
Comment *
File
* = required field[▶ Show post options & limits]
Confused? See the FAQ.
Embed
(replaces files and can be used instead)
Options
dicesidesmodifier
Password (For file and post deletion.)

Allowed file types:jpg, jpeg, gif, png, webm, mp4, swf, pdf
Max filesize is 8 MB.
Max image dimensions are 10000 x 10000.
You may upload 5 per post.


Oh, hey. We're actually having old posts pruned now.

 No.2524

So what do spergs think of random number theory?

For example, password/passphrase security.

Some people recommend the diceware method. Then there's this site: google: "how big is your haystack which claims to test password strength.

Here is an example passphrase from the diceware site:

strop 17 aw tete karp

24 character password from random org:

jappHzuMCtJw6TwKXqwL2BHU

33.64 million trillion centuries

0000000000000?

10.34 centuries

bullshit bullshit bullshit

35.64 billion trillion centuries

…something just ain't adding up here…

Massive Cracking Array Scenario:

(Assuming one hundred trillion guesses per second) :

1.33 thousand trillion centuries

 No.2525

hit post too soon

from diceware (and metric used for results all other examples):

strop 17 aw tete karp

Massive Cracking Array Scenario:

(Assuming one hundred trillion guesses per second) :

1.33 thousand trillion centuries


 No.2526

hotwheels

0.0565 seconds


 No.2529

wassup muh nigga, how you be?

7.32 thousand trillion trillion centuries


 No.2544

These sites are made for normalfags to share on facebook and feel amazed at how cool science is. They are next to useless except as rudimentary tools.

Time to crack, entropy, etc. is impossible to calculate just from the data itself. Here's a random string:

>KGJGZHVLNC

What's the entropy? Entropy is just the logarithm of all possibilities, so let's look at those.

If you assume that the rule is "uppercase letters" there are 26^10. But how do you know they were English letters? If the Czech alphabet was used, you get 42^10. How do you know they were all uppercase? What if I generated mixed case and just happened to get only upper case ones? What if my alphabet was in fact CGHJKLNZ? You won't see A in there, why do you assume it was a possibility?

In fact, what if my generation method was:


Pick random integer x s.t. 0>x>=1
if x==1 return KGJGZHVLNC

Then the entropy is 0.

You see now that entropy is entirely dependent on context. With passwords, the question is, what does the hacker think your password will be? If the hacker is a retard who tries every combination of every ASCII character, first for 1 char, then 2 chars, etc. Then aaaaaaaaaaaaaaaaaaaaaaaaaaa is an excellent password with superb entropy. If your password is "strop 17 aw tete karp", the entropy depends on what the hacker thinks. Does he expect that your password could be any string? Then he will have to try everything and entropy is high. Does he somehow expect that you will have a password made of words, then he can look for dictionary words delimited by spaces, and entropy is lower.

In reality, hackers don't sit around trying to guess what your password is. Every time news breaks out about x million compromised accounts, they obtain that list, add it to other lists they already have, and make a list of top X most common passwords. When hacking you (more like hacking millions of people at once which happen to also include you), they try the X most common passwords (or password patterns), and if none work for your account move on. A proper password strength checker would have such a list, and determine password strength according to that. These password strength checker sites are just useless toys that try to cash in on security hysteria.


 No.2559

>>2544

I love you


 No.2565

>>2559

Its stuff like this that makes me wish that /sci/ here had more posters.




[Return][Go to top][Catalog][Post a Reply]
Delete Post [ ]
[]
[ home / board list / faq / random / create / bans / search / manage / irc ] [ ]