Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Upthread we have someone boasting about naming their business machines after porn stars.


Why does that bother you so much?


I had to learn the hard way


I worked with home support for an ISP. A few times I was at a customer helping with a router and the mother call her son to get the password for the router. Not always a nice password...


I very much believe in offensive passwords/passphrases (maybe not for wireless routers) specifically because:

(a) You're not supposed to tell anybody what they are.

(b) Offensive passphrases are easier to remember.


Also easier to crack if an attacker knows that detail.


Not that it narrows it down that much.


You could probably throw out 90% or more of dictionary words for your permutations, I'd say that is significant enough to paint a target on your back.


If your password is derived from a four word phrase (per the XKCD formula, which isn’t the only one), potentially all of the individual words could be inoffensive in isolation. There’s no obvious way to operationalize the human intuition of offense in a way that restricts the search space if you’re smart about it.


It all depends on if you have anything worth cracking. Sure, if your average hn reader encrypts a password db with a dirty four word phrase, that reader will be fine because no one is willing to rub two pennies together to crack that.

On the other hand if you're protecting secrets actually worth something...


Hey, for all you know I might find certain seemingly random 128-character alphanumeric strings very offensive ;)


Seemingly random isn't random.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: