Reply to post: The entropic decrease of entropy

If you're despairing at staff sharing admin passwords, look on the bright side. That's CIA-grade security

Brewster's Angle Grinder Silver badge

The entropic decrease of entropy

We're confusing two different things - statistical randomness and predictability. We really want passwords that are unpredictable but we use statistical randomness as a proxy since it's all but impossible to know whether a string of bits is predictable.

This is deep philosophical water. But if our dictionary of predictable strings constantly expands then the likelihood of password being predicted increases with time. So "entropy" (randomness) of passwords decreases over time until we hit a tipping point when the dictionary becomes unmanageably big. At which point we have to remove the least likely passwords - for predictable values of "least likely".

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon