
Think I've been doing my passwords wrong for like ten years
I do feel kinda dumb for how many hours I spent memorizing weird symbols in my passwords, thinking I was being "unhackable". Now I'm seeing this in an article and it wasn't actually protecting me from anything. because having an 8 or 10 character password with numbers and symbols is actually weaker then just using a super long 15+ character passphrase that's just random words.
and it's (mostly) all about raw computing power that changed things recently. like, if your password is only 8 characters its basically instant for a modern rig to guess it. the pic mentions these rigs do over 100 billion guesses per second which is just... how is that even possible lol. its actually terrifying. basically 15 characters is the new "floor" for security now according to NIST.
already started moving everything to longer passphrases and finally bothered to turn on MFA for my secondary accounts. apparently MFA blocks like 99.9% of automated attacks so idk why i waited this long. anyway just a sudden realization that my "complex" 8-10 character mess was actually trash.