Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Thanks, that is interesting and kind of matches my reasoning.

I have a feeling the debate is a bit colored by leftover paranoia from the times when several users shared one computer and the password database was easy to get hold of.

Unless the attacker somehow manages to grab your password database (and not your content, which would be an interesting setup in itself) he won't be able to brute force you. He will only be able to lucky-guess you. And you don't need 24 random characters to block a lucky guess scheme. :)



This was my thought as well, I've never heard of a brute force attempt working in the real world.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: