this post was submitted on 20 Aug 2024
195 points (95.8% liked)

Asklemmy

43851 readers
706 users here now

A loosely moderated place to ask open-ended questions

Search asklemmy ๐Ÿ”

If your post meets the following criteria, it's welcome here!

  1. Open-ended question
  2. Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
  3. Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
  4. Not ad nauseam inducing: please make sure it is a question that would be new to most members
  5. An actual topic of discussion

Looking for support?

Looking for a community?

~Icon~ ~by~ ~@Double_A@discuss.tchncs.de~

founded 5 years ago
MODERATORS
 

For me it's the paranoia surrounding webcams. People outright refuse to own one and I understand, until they go on and on about how they're being spied. Here's the secret - unplug the damn thing when you think you won't use it or haven't used it in a while.

They, whoever it is, can't really spy on you on something that's already off and unplugged!

you are viewing a single comment's thread
view the rest of the comments
[โ€“] cmfhsu@lemmy.world 1 points 2 months ago* (last edited 2 months ago) (1 children)

I think I'm confused on your point.

I interpreted your statement to mean "adding a requirement for certain types of characters will decrease the number of possible passwords compared to no requirements at all", which is false. Even in your example above, with only two letters, no numbers / special characters allowed, requiring a capital letter decreases the possibilities back to the original 676 possible passwords - not less.

Perhaps you're trying to say that passwords should all require certain complexity, but without broadcasting the password requirements publicly? I suppose that's a valid point, but I don't think the tradeoff of time required to make that secure is worth the literal .000001% (I think I did the math right) improvement in security.

[โ€“] Don_alForno@feddit.org 3 points 2 months ago

Even in your example above, with only two letters, no numbers / special characters allowed, requiring a capital letter decreases the possibilities back to the original 676 possible passwords - not less.

No it doesn't. It reduces the possibilities to less than the 52x52 possibilities that would exist if you allowed all possible combinations of upper and lower case letters.

You are confused because you only see the two options of enforcing or not allowing certain characters. All characters need to be allowed but none should be enforced. That maximizes the number of possible combinations.

that passwords should all require certain complexity, but without broadcasting the password requirements publicly?

No, because that's still the same. An attacker can find out the rules by creating accounts and testing.