• Mohamed
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 day ago

    Yes and no, in my opinion. Attackers can keep a list of all compromised passwords, and try it even for accoints that may not be associated. This is a much smaller search space than to go through every possible password of length <= 32 (for example).