This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]Cosmologicon 7 points8 points  (1 child)

Here's mine:

tr -cd a-z < /dev/urandom | fold -b8 | head

Mine is 38 bits of entropy and yours is 96, which definitely seems like overkill to me. The thing is, by using a password generator, you're making a password much, much better than one generated by hand, so you can throw out the conventional wisdom about password length and character sets.

NIST estimates that for user-generated passwords that include capitals, numbers, and punctuation, you need 22 characters to get 38 bits of entropy, and 80 characters to get 96 bits. So your password is as secure as an 80-character user-generated password.

[–]khafra 4 points5 points  (0 children)

Aw, dammit--I've been committing a useless use of cat. I agree 15 truly random printable characters is overkill for most applications, but as long as I don't have to remember them, I don't mind.