Bitcoin Forum
July 12, 2017, 03:45:18 PM *
News: Latest stable version of Bitcoin Core: 0.14.2  [Torrent].
 
   Home   Help Search Donate Login Register  
Pages: [1]
  Print  
Author Topic: How strong should temporary passphrase be?  (Read 436 times)
smesv
Newbie
*
Offline Offline

Activity: 13


View Profile
June 07, 2017, 12:08:31 AM
 #1

I want to protect against brute force guessing my passphrase I added to 24 word seed in case it gets stolen. Is it hard to brute force with computer if phrase is too simple? How many guesses can be made per second?
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction. Advertise here.
1499874318
Hero Member
*
Offline Offline

Posts: 1499874318

View Profile Personal Message (Offline)

Ignore
1499874318
Reply with quote  #2

1499874318
Report to moderator
pooya87
Legendary
*
Offline Offline

Activity: 966

Bitcoin's dominance=100,000 merchants accepting it


View Profile
June 07, 2017, 03:52:51 AM
 #2

first to clarify, when using a wallet you set the password on your wallet file not the seed, the seed may be written in the wallet file and it will be encrypted with the password.
when writing down your password it can be stolen and used to gain access to the funds, the password you set on your wallet file doesn't change this.

for strong password you can read this https://en.wikipedia.org/wiki/Password_strength and find a lot more articles about it. but in summary, it should be
- long
- containing uppercase and lowercase letters, numbers, symbols
- it should not be regular words such as words of a poem, a popular sentence or something similar.

simple example using a random online tool: -4oC6vY317Z6S)s

vh
Sr. Member
****
Offline Offline

Activity: 448


View Profile
June 07, 2017, 04:01:38 AM
 #3

I added to 24 word seed in case it gets stolen. Is it hard to brute force with computer if phrase is too simple?

If you are talking about BIP39 each word is derived down to only ~11bits of security for a total entropy of 2^256. 
As long as you use on average 2 letters per word, I believe brute forcing it will take the same amount of time as a "difficult" to remember 24 word phrase.

smesv
Newbie
*
Offline Offline

Activity: 13


View Profile
June 07, 2017, 06:26:44 AM
 #4

I was talking about passphrase aka 25th seed word. How complex shoudl it be t oprotect if someone finds seed words and tries to brute force 25th word.
EastBirth
Jr. Member
*
Offline Offline

Activity: 53

Blocklancer - Freelance on the Blockchain


View Profile
July 11, 2017, 09:42:27 AM
 #5

It really doesn't matter. The ones you are given are so random. How will anyone guess that many words and in the right order unless it's a sentence ? Don't worry about it.

Pages: [1]
  Print  
 
Jump to:  

Sponsored by , a Bitcoin-accepting VPN.
Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!