Taking over historically grown IT is hell

  • rekabis@lemmy.ca
    link
    fedilink
    arrow-up
    5
    ·
    1 day ago

    And more and more businesses are also limiting what characters you use, as well.

    Like, my random generator uses characters from the entire European UTF-8 printable character set. This expands the number of usable characters from about 68-74 (the typical uppercase, lowercase, 0-9 & special characters) to about 1,200 characters. This includes all Latin, Cyrillic, and Greek variations used across Europe.

    Just using the wider UTF-8 range nearly always doubles the bitwise complexity (as KeePass measures it) for passwords of the same length, if not more, thereby dramatically reducing the ability for the password to be brute-forced. Not to mention using characters that are not expected to be in passwords in the first place - most brute forcing simply doesn’t account for that where a primarily English-speaking victim set is concerned.

    Plus, the passwords are not short. I usually prefer 32 characters, and in important/mission-critical services I expand it to 64 characters.