Posted on Nov 23, 2017
Passwords: Using 3 Random Words Is A Really Bad Idea!
517
5
2
2
2
0
Posted 7 y ago
Responses: 2
So there are a few assumptions here.
Of course a truly random password is always better. But it's unrealistic to expect a user to remember a password like: Sg+U@lS6A10%
The average person simply doesn't have the mental capacity to do it. That's why password Managers like LastPass become are a must.
However compared to something like password123 a random 3 or 4 word password is better. Sure it's not unbreakable but nothing is.
The second assumption is that the user is picking their random words. Like the article says your now limiting the base to the users possible vocabulary, but I'd a machine picks them you're much better off.
In reality users need to stop expecting passwords to be their defense.
Use a password manager and 2 Factor Authentication.
Of course a truly random password is always better. But it's unrealistic to expect a user to remember a password like: Sg+U@lS6A10%
The average person simply doesn't have the mental capacity to do it. That's why password Managers like LastPass become are a must.
However compared to something like password123 a random 3 or 4 word password is better. Sure it's not unbreakable but nothing is.
The second assumption is that the user is picking their random words. Like the article says your now limiting the base to the users possible vocabulary, but I'd a machine picks them you're much better off.
In reality users need to stop expecting passwords to be their defense.
Use a password manager and 2 Factor Authentication.
(1)
(0)
Read This Next