Password length
Password length
Posted May 16, 2013 12:56 UTC (Thu) by robbe (guest, #16131)In reply to: Fedora's invisible passwords and visible squabbles by Baylink
Parent article: Fedora's invisible passwords and visible squabbles
> Those who note that asterisks are bad are also correct; knowing the length
> of the password substantially reduces the effort to crack it.
> of the password substantially reduces the effort to crack it.
Depends on your definition of "substantial". For the cases I computed, and that I consider relevant, the effort reduction is not even half. Not what I would call a good safety margin.
The more important advantage an attacker gains by seeing the (approximate) password length is being able to weed out "too hard" passwords, and just attack accounts with easier ones.
