Password Creation in the Presence of Blacklists, USEC '17, http://www.passwordresearch.com/papers/paper650.html … Didn't measure such a large blacklist though.
I know math is hard, but am I seriously the only one capable of mentally guesstimating the coverage of a 300M blacklist?
-
-
"monkey1" isn't in the top1k and is barely in the top10k. To pass the 300M blacklist all you need is "monkey%33". This stuff is exponential.
-
FFS, the 300M blocklist only covers 37% of /usr/share/dict/words, with no numbers or other transformations!
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.