You're looking at Less Wrong's discussion board. This includes all posts, including those that haven't been promoted to the front page yet. For more information, see About Less Wrong.

Nornagest comments on Open thread Jan. 5-11, 2015 - Less Wrong Discussion

2 Post author: polymathwannabe 05 January 2015 12:48PM

You are viewing a comment permalink. View the original post to see all comments and the full post content.

Comments (150)

You are viewing a single comment's thread. Show more comments above.

Comment author: Nornagest 05 January 2015 06:10:08PM *  7 points [-]

That comic makes a good argument against the kinds of alphanumeric passwords most people naively come up with to match password policies, but the randomized ones that a password manager will give you are far stronger. Assuming 6 bits of entropy per character (equivalent to a choice of 64 characters) and a good source of randomness, a random 8-character password is stronger than "correct horse battery staple" (48 bits of entropy vs. ~44), and 10 characters (for 60 bits of entropy) blows it out of the water.

Of course, since you typically won't be able to remember eight base64 characters for each of the fifty sites you need a password for, that makes the security of the entire system depend on that of the password manager or wherever else you're storing your passwords. A mix of systems might work best in practice, and I'd recommend using two-factor authentication where it's offered on anything you really need secured.