Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sure that's fine for things that truly don't matter, but if you're using a password manager then you might as well generate more characters. Bear in mind there is no guarantee that services storing your passwords are using something like bcrypt with slow settings. I've definitely seen things like PBKDF2 set to comically low iterations or even raw sha/md5.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: