• Toes♀@ani.social
    link
    fedilink
    arrow-up
    4
    arrow-down
    1
    ·
    edit-2
    20 hours ago

    So, I was having trouble sleeping last night and found myself mulling over your idea.

    As any good sleep deprived tech I went down a rabbit hole. There are solutions that prepare the encrypted payload on the client side. But, why you don’t see solutions offering you to authenticate with the entire lotr series is that you hit a ceiling really fast where more data is the same security threshold as the former smaller data.

    If you want to derive security from large data there’s already a scalable solution in the form of private public key pairs, where the size of the key is directly tied to the security. So if you convert lotr to a prime number you can get somewhere with that approach.

    • NiHaDuncan@lemmy.world
      link
      fedilink
      arrow-up
      2
      ·
      6 hours ago

      I’ve thought of the point where password length becomes irrelevant as well. Unless there some maths I don’t know that plays a role here, longer passwords become useless when x^n > K. Where x is the character set available for the password, n is the smallest length that meets the criteria of the formula, and K is the hash functions key space. Effectively, this would be due to the fact that brute forcing would be just as likely to find a collision as it would the actual password used.